Data security processing method, communication device, communication system and storage medium

CN121890133APending Publication Date: 2026-04-17BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2024-08-15
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In 6G mobile communication systems, how can we ensure communication security when the terminal communicates directly with network functions (NF) other than the access management function (AMF)?

Method used

Through message interaction between the terminal and the first node, a security algorithm is negotiated and a key is generated to protect the communication security between the terminal and the second node, and to allow the terminal to establish communication security directly with the second node, independent of the security algorithm and key with the third node.

Benefits of technology

It improves the security of communication between the terminal and the second node, and generates different keys for terminals and second nodes with different security capabilities, thereby enhancing the security isolation and adaptability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121890133A_ABST
    Figure CN121890133A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data security processing method, communication equipment, a communication system, a storage medium and a program product. The method is executed by a terminal, and the method comprises the following steps: sending a first message to a first node, the first message being used for enabling a second node to determine a first security algorithm; receiving a second message sent by the first node; the second message is used for the terminal to determine a first security algorithm; generating a second key based on the first security algorithm and the first key; the second key is used for protecting communication security between the terminal and the second node. According to the technical scheme provided by the embodiment of the invention, the first message and the second message are utilized, so that the terminal acquires the first security algorithm selected by the second node based on the first message, and security algorithm negotiation between the terminal and the second node is realized. And the second key is generated based on the first security algorithm and the first key, the communication security between the terminal and the second node is protected through the second key, and the communication security between the terminal and the second node is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Data security processing method, communication device, communication system and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to a data security processing method, a communication device, a communication system, a storage medium and a program product. BACKGROUND

[0002] The sixth generation mobile communication system (6 th Generantion, 6G) architecture needs to streamline network functions (Network Function, NF). Streamlined NF has significant advantages in capacity, coverage, signaling overhead, scaling and energy overhead.

[0003] SUMMARY

[0004] In the case of allowing a terminal to directly communicate with an NF other than an access management function (Access Management Function, AMF), how to ensure communication security.

[0005] The present disclosure provides a data security processing method, a communication device, a communication system, a storage medium and a program product.

[0006] According to a first aspect of the embodiments of the present disclosure, a data security processing method is provided, wherein the method is performed by a terminal, and the method comprises: sending a first message to a first node, the first message being used for a second node to determine a first security algorithm; receiving a second message sent by the first node; the second message is provided by the second node and is used for the terminal to determine the first security algorithm; generating a second key based on the first security algorithm and a first key; the second key is used to protect the security of communication between the terminal and the second node; and the first key is generated according to a third key of a third node.

[0007] According to a second aspect of the embodiments of the present disclosure, a data security processing method is provided, wherein the method is performed by a second node, and the method comprises: receiving a first message sent by a first node or a third node, the first message being used for the second node to determine a first security algorithm; generating a fifth key based on the first security algorithm and a sixth key, the fifth key being used to protect the security of communication between the second node and a terminal; the sixth key is generated according to a third key of a third node; sending a second message to the terminal through the first node; and the second message is used for the terminal to determine the first security algorithm.

[0008] According to a third aspect of embodiments of the present disclosure, a data security processing method is provided, wherein the method is performed by a third node, and the method comprises: generating a sixth key according to a third key of the third node; and sending the sixth key to a second node, the sixth key being used by the second node to generate a fifth key, the fifth key being used to protect communication security between the second node and a terminal.

[0009] According to a fourth aspect of embodiments of the present disclosure, a data security processing method is provided, wherein the method is performed by a first node, and the method comprises: receiving a first message sent by a terminal; sending the first message to a second node or a third node, the first message being used by the second node to determine a first security algorithm; receiving a second message sent by the second node; and sending the second message to the terminal, the second message being used by the terminal to determine the first security algorithm; the first security algorithm being used by the terminal to generate a second key, the second key being used to protect communication security between the terminal and the second node.

[0010] According to a fifth aspect of embodiments of the present disclosure, a data security processing method is provided, wherein the method is performed by a communication system, and the method comprises: a terminal sending a first message to a first node; the first node sending the first message to a second node or a third node; the first message being used by the second node to determine a first security algorithm; the third node generating a sixth key according to a third key of the third node; the third node sending the sixth key to the second node; the second node generating a fifth key based on the first security algorithm and the sixth key, the fifth key being used to protect communication security between the second node and the terminal; the second node sending a second message to the first node; the first node sending the second message to the terminal; the second message being used by the terminal to determine the first security algorithm; the terminal generating a second key based on the first security algorithm and a first key; the second key being used to protect communication security between the terminal and the second node; the first key being generated according to the third key of the third node.

[0011] According to a sixth aspect of embodiments of the present disclosure, a terminal is provided, wherein the terminal comprises: a sending module configured to send a first message to a first node, the first message being used by a second node to determine a first security algorithm; a receiving module configured to receive a second message sent by the first node; the second message being provided by the second node and the second message being used by the terminal to determine the first security algorithm; and a processing module configured to generate a second key based on the first security algorithm and a first key; the second key being used to protect communication security between the terminal and the second node; the first key being generated according to a third key of a third node.

[0012] According to a seventh aspect of embodiments of the present disclosure, a second node is provided, wherein the second node comprises: a receiving module configured to receive a first message sent by a first node or a third node, the first message being used for the second node to determine a first security algorithm; a processing module configured to generate a fifth key based on the first security algorithm and a sixth key, the fifth key being used for protecting communication security between the second node and a terminal; the sixth key being generated according to a third key of the third node; and a sending module configured to send a second message to the terminal through the first node; the second message being used for the terminal to determine the first security algorithm.

[0013] According to an eighth aspect of embodiments of the present disclosure, a third node is provided, wherein the third node comprises: a processing module configured to generate a sixth key according to a third key of the third node; and a sending module configured to send the sixth key to a second node, the sixth key being used for the second node to generate a fifth key, the fifth key being used for protecting communication security between the second node and a terminal.

[0014] According to a ninth aspect of embodiments of the present disclosure, a first node is provided, wherein the first node comprises: a receiving module configured to receive a first message sent by a terminal; and a sending module configured to send the first message to a second node or a third node, the first message being used for the second node to determine a first security algorithm; the receiving module is further configured to receive a second message sent by the second node; and the sending module is further configured to send the second message to the terminal, the second message being used for the terminal to determine the first security algorithm; the first security algorithm being used for the terminal to generate a second key, the second key being used for protecting communication security between the terminal and the second node.

[0015] According to a tenth aspect of embodiments of the present disclosure, a communication system is provided, wherein the communication system comprises a terminal, a first node, a second node and a third node, the terminal is configured to implement the data security processing method provided in the first aspect, the second node is configured to implement the data security processing method provided in the second aspect, the third node is configured to implement the data security processing method provided in the third aspect, and the first node is configured to implement the data security processing method provided in the fourth aspect.

[0016] According to an eleventh aspect of embodiments of the present disclosure, a communication device is provided, wherein the communication device comprises:

[0017] one or more processors;

[0018] The processor is configured to invoke instructions to cause the communication device to perform the data security processing method provided in the first aspect, the second aspect, the third aspect or the fourth aspect.

[0019] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, when the instructions are executed on a communication device, the communication device executes the data security processing method provided in the first aspect, the second aspect, the third aspect or the fourth aspect.

[0020] According to a thirteenth aspect of the embodiments of the present disclosure, a program product is provided, wherein the program product comprises a computer program, when the computer program is executed by a communication device, the communication device can implement the data security processing method provided in the first aspect, the second aspect, the third aspect or the fourth aspect.

[0021] The technical solution provided by the embodiments of the present disclosure is that the terminal sends a first message to a first node, and receives a second message sent by the first node, to learn a first security algorithm selected by a second node based on the first message, so as to realize security algorithm negotiation between the terminal and the second node. And a second key is generated based on the negotiated first security algorithm and a first key, and the communication security between the terminal and the second node is protected by the second key. In this way, in addition to allowing the terminal to directly establish communication security with a third node, the terminal is also allowed to directly establish communication security with the second node, and the first security algorithm negotiated between the terminal and the second node and the security algorithm negotiated between the terminal and the third node are independent of each other, and the generated second keys are also independent of each other, which is beneficial to improving the security of communication between the terminal and the second node on the one hand, and can adapt to different security capabilities of the terminal and the second node to generate different second keys on the other hand.

[0022] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0023] The accompanying drawings, which are incorporated into and form part of the specification, illustrate the embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the embodiments of the present disclosure.

[0024] FIG. 1A is a schematic diagram of an architecture of a communication system according to an example embodiment;

[0025] FIG. 1B is a schematic diagram of a network architecture according to an example embodiment;

[0026] FIG. 1C is a schematic diagram of a 6G network architecture according to an example embodiment;

[0027] FIG. 1D is a schematic diagram of a 6G network architecture according to an example embodiment;

[0028] FIG. 1E is a diagram illustrating a key hierarchy in a 5G network, according to an example embodiment.

[0029] FIG. 2A is a diagram illustrating interactions of a data security processing method, according to an example embodiment;

[0030] FIG. 2B is a diagram illustrating interactions of a data security processing method, according to an example embodiment;

[0031] FIG. 2C is a diagram illustrating interactions of a data security processing method, according to an example embodiment;

[0032] FIG. 3A is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0033] FIG. 3B is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0034] FIG. 3C is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0035] FIG. 4A is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0036] FIG. 4B is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0037] FIG. 4C is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0038] FIG. 5A is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0039] FIG. 5B is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0040] FIG. 5C is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0041] FIG. 6A is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0042] FIG. 6B is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0043] FIG. 6C is a diagram illustrating a flow of a data security processing method, according to an example embodiment;

[0044] FIG. 7 is a diagram illustrating interactions of a data security processing method, according to an example embodiment;

[0045] FIG. 8A is a diagram illustrating a key hierarchy structure 1 according to an example embodiment;

[0046] FIG. 8B is a diagram illustrating a key hierarchy structure 2 according to an example embodiment;

[0047] FIG. 8C is a diagram illustrating a key hierarchy structure 3 according to an example embodiment;

[0048] FIG. 8D is a diagram illustrating interactions for NAS security establishment by AMF generating keys according to an example embodiment;

[0049] FIG. 8E is a diagram illustrating a key hierarchy structure 4 according to an example embodiment;

[0050] FIG. 8F is a diagram illustrating interactions for NAS security establishment by SEAF or AMF generating keys according to an example embodiment;

[0051] FIG. 9A is a diagram illustrating a structure of a terminal according to an example embodiment;

[0052] FIG. 9B is a diagram illustrating a structure of a second node according to an example embodiment;

[0053] FIG. 9C is a diagram illustrating a structure of a third node according to an example embodiment;

[0054] FIG. 9D is a diagram illustrating a structure of a first node according to an example embodiment;

[0055] FIG. 10A is a diagram illustrating a structure of a communication device according to an example embodiment;

[0056] FIG. 10B is a diagram illustrating a structure of a chip according to an example embodiment. DETAILED DESCRIPTION

[0057] Embodiments of the present disclosure provide a data security processing method, a communication device, a communication system, a storage medium, and a program product.

[0058] In a first aspect, the embodiments of the present disclosure provide a data security processing method, wherein the method is performed by a terminal, and the method comprises: sending a first message to a first node, the first message being used for the first node to determine a first security algorithm; receiving a second message sent by the first node; the second message being provided by a second node and being used for the terminal to determine the first security algorithm; generating a second key based on the first security algorithm and a first key; the second key being used for protecting the security of communication between the terminal and the second node; and the first key being generated according to a third key of a third node.

[0059] In the above embodiment, the terminal learns the first security algorithm selected by the second node based on the first message by sending the first message to the first node and receiving the second message sent by the first node, thereby realizing the security algorithm negotiation between the terminal and the second node. And the second key is generated based on the negotiated first security algorithm and the first key, and the communication security between the terminal and the second node is protected by the second key. In this way, the terminal can not only directly establish communication security with the third node, but also directly establish communication security with the second node. Moreover, the first security algorithm negotiated between the terminal and the second node and the security algorithm negotiated between the terminal and the third node are independent of each other, and the generated second keys are also independent of each other. On the one hand, it is beneficial to improve the security of communication between the terminal and the second node; on the other hand, it can adapt to different security capabilities of the terminal and the second node to generate different second keys.

[0060] In some embodiments of the first aspect, the sending the first message to the first node comprises one of the following:

[0061] sending a first radio resource control (RRC) message to the first node; the first RRC message comprising the first message protected by a fourth key; and the fourth key being used for protecting the security of communication between the terminal and the third node.

[0062] sending a second RRC message to the first node; the second RRC message comprising the first message not protected by the fourth key. In the above embodiment, in the case of forwarding the first message to the second node via the third node, the first message is protected by the existing fourth key between the terminal and the third node; and the security of the first message is improved. In the case of not forwarding the first message to the second node via the third node, since the security context between the terminal and the second node is not established, the first message not protected by the fourth key is sent through the second RRC message, so that the second node without the security context can correctly interpret the first message, so as to perform subsequent security algorithm negotiation and other processes based on the message content of the received first message.

[0063] In some embodiments of the first aspect, the first RRC message comprises at least one of: a first indicator indicating a message type of the first message; a second indicator indicating that the first node forwards the first message to a third node; type information of the second node; an instance ID of the second node.

[0064] In the above embodiments, the first indicator or the second indicator carried in the first RRC message facilitates the first node to determine that the third node is a forwarding node of the first message, and to send the first message to the third node, thereby realizing the transparent transmission of the first message. Furthermore, the type information of the second node or the instance ID of the second node is carried in the first RRC message, which facilitates the first node and / or the third node to determine the second node.

[0065] In some embodiments of the first aspect, the second RRC message comprises at least one of: a first indicator indicating a message type of the first message; type information of the second node; an instance ID of the second node.

[0066] In the above embodiments, the first indicator, the type information of the second node or the instance ID of the second node is carried in the second RRC message instead of the first message, which facilitates the first node to determine the second node, and thus realizes the transparent transmission of the first message.

[0067] In some embodiments of the first aspect, the first RRC message is protected by an access stratum (AS) security context of the terminal.

[0068] In the above embodiments, the first RRC message is protected by the AS security context, thereby ensuring the security of the first message on the air interface.

[0069] In some embodiments of the first aspect, the second RRC message is protected by an access stratum (AS) security context of the terminal.

[0070] In the above embodiments, the second RRC message is protected by the AS security context, thereby ensuring the security of the first message on the air interface.

[0071] In some embodiments of the first aspect, the receiving the second message sent by the first node comprises:

[0072] receiving a third RRC message sent by the first node, wherein the third RRC message comprises the second message, and the second message is integrity protected by a fifth key; and the fifth key is generated according to a sixth key and the first security algorithm.

[0073] In the above embodiment, the terminal receives a third RRC message from the first node, the third RRC message including a second message which is integrity protected by a fifth key, the fifth key being generated by the second node according to a sixth key and the first security algorithm; on the one hand, the terminal can learn the first security algorithm selected by the second node based on the second message to generate the second key; on the other hand, it is conducive to the terminal to verify the integrity of the second message by the generated second key, to verify the establishment of the shared security context between the terminal and the second node; and the success of establishing the shared security context between the terminal and the second node is improved.

[0074] In some embodiments of the first aspect, the second message includes at least one of: algorithm identification information, used to identify the first security algorithm; and second information, used to indicate a first capability of the terminal, the first capability being security-related.

[0075] In the above embodiment, by carrying the algorithm identification information and / or the first capability of the terminal in the second message, it is conducive for the terminal to learn the security algorithm selected by the second node, and to realize the security algorithm negotiation between the terminal and the second node.

[0076] In some embodiments of the first aspect, the generating the second key based on the first security algorithm and the first key includes one of:

[0077] generating the second key based on the first key, the algorithm identification information, and algorithm type information;

[0078] generating the second key based on the first key, the algorithm identification information, a length of the algorithm identification information, the algorithm type information, and a length of the algorithm type information.

[0079] In the above embodiment, two schemes for generating the second key are provided, and the algorithm identification information and the algorithm type information of the security algorithm negotiated by the terminal and the second node are introduced in the process of generating the second key, so that the security capability matching of the terminal and the second node is considered when generating the second key; in the case that the security algorithm negotiated by the terminal and each second node is different, the generated second key is also different, thereby improving the communication security isolation between the terminal and each second node.

[0080] In some embodiments of the first aspect, the method further includes:

[0081] sending a fourth RRC message to the first node, the fourth RRC message including an indication that the first security algorithm negotiation is complete.

[0082] In the above embodiments, after the terminal generates the second key, an indication that the first security algorithm is negotiated can be encapsulated in the fourth RRC message, and the indication that the first security algorithm is negotiated is sent to the first node using the RRC connection between the terminal and the first node, so that the first node transmits or forwards the indication to the subsequent node. In some embodiments of the first aspect, the method further comprises:

[0083] receiving the fifth RRC message sent by the first node, the fifth RRC message comprising the third message, the third message being a response message of the first message sent by the terminal.

[0084] In the above embodiments, the terminal receives the fifth RRC message from the first node, and the fifth RRC message comprises the third message, the third message being a response message of the first message sent by the terminal to the second node, so that the terminal realizes one communication with the second node; and the third message is protected by the fifth key, which is conducive to improving the security of the third message.

[0085] In some embodiments of the first aspect, the method further comprises: the first message comprising at least one of the following: NAS signaling; an identifier ID of the terminal; a first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node.

[0086] In the above embodiments, by carrying at least one of the above information contents in the first message, the third node or the second node can know the communication demand of the UE and / or obtain the input parameter for generating the sixth key.

[0087] In some embodiments of the first aspect, the method further comprises one of the following:

[0088] generating the first key according to the third key, the first count value, and type information of the second node;

[0089] generating the first key according to the third key, the first count value, and an instance ID of the second node.

[0090] In the above embodiments, the first key can be generated according to the third key, the first count value, and the type of the second node, so that the terminal can generate the first key without knowing the specific second node, which simplifies the generation of the first key. Alternatively, the first key can be generated according to the third key, the first count value, and the instance ID of the second node, so that the second key generated is different for different second nodes, which further improves the security of the communication between the UE and the second node.

[0091] In a second aspect, the embodiments of the present disclosure provide a data security processing method, wherein the method is performed by a second node, and the method comprises: receiving a first message sent by a first node or a third node, the first message being used for the second node to determine a first security algorithm; generating a fifth key based on the first security algorithm and a sixth key, the fifth key being used for protecting the communication security between the second node and a terminal; the sixth key being generated according to a third key of the third node; sending a second message to the terminal through the first node; the second message being used for the terminal to determine the first security algorithm.

[0092] In the above embodiment, the second node selects the first security algorithm based on the received first message, and forwards the second message to the terminal through the first node, so as to inform the terminal of the first security algorithm selected by the second node by using the second message, and to realize the security algorithm negotiation between the terminal and the second node. Moreover, the second node generates the fifth key based on the selected first security algorithm and the sixth key, and protects the communication security between the second node and the terminal by using the fifth key. On the one hand, the first security algorithms negotiated between the terminal and each second node are different, and the generated second keys are also different, which is beneficial to improving the security isolation of the communication between the terminal and each second node; on the other hand, different second keys can be generated according to the different security capabilities of the terminal and each second node.

[0093] In some embodiments of the second aspect, the receiving the first message sent by the first node or the third node comprises:

[0094] receiving a fourth message sent by the third node, the fourth message comprising at least one of the following: the first message decoded based on a fourth key; the sixth key; second information used for indicating a first capability of the terminal, the first capability being related to security; identification information of the first node; address information of the first node.

[0095] In the above embodiment, at least one of the above information contents is carried by the fourth message, so that the second node knows the communication requirement of the UE and / or obtains the input parameter for generating the fifth key. Moreover, in the case of forwarding the first message to the second node through the third node, the second node receives the first message from the terminal by receiving the fourth message sent by the third node; the first message is protected by using the existing fourth key between the terminal and the third node when the first message is transmitted between the terminal and the third node; and the security of the first message is improved.

[0096] In some embodiments of the second aspect, the receiving the first message sent by the first node or the third node comprises:

[0097] receive a fifth message sent by the first node, the fifth message comprising at least one of: the first message unprotected by the fourth key; and second information indicating a first capability of the terminal, the first capability being related to security.

[0098] In the above embodiments, at least one of the above information contents is carried by the fifth message, so that the second node is able to determine the first security algorithm and / or obtain the input parameter for generating the fifth key; and in the case that the first message is not forwarded to the second node via the third node, the first message unprotected by the fourth key is received due to the fact that no security context is established between the terminal and the second node, so that the first message can be interpreted by the second node without security context.

[0099] In some embodiments of the second aspect, the method further comprises:

[0100] sending a sixth message to the third node, the sixth message being used to request the third node to generate the sixth key for the second node;

[0101] receiving a seventh message sent by the third node, the seventh message comprising the sixth key.

[0102] In the above embodiments, in the case that the first node directly forwards the first message to the second node, the second node sends a sixth message to the third node to request the third node to generate the sixth key for the second node, and obtains the sixth key by receiving a seventh message sent by the third node. Since the sixth key is an intermediate key for generating the fifth key, the second node is able to generate the fifth key based on the sixth key generated by the third node.

[0103] In some embodiments of the second aspect, the method further comprises:

[0104] determining fourth information according to the second information and third information, the third information being used to indicate the first capability of the second node, and the fourth information being used to indicate a first security algorithm selected by the second node.

[0105] In the above embodiments, the second node selects a suitable first security algorithm based on its own security capability and the security capability of the terminal indicated by the second information, so as to adapt to different security capability matching cases of the terminal and the second node to generate different second keys.

[0106] In some embodiments of the second aspect, the fourth information comprises algorithm identification information used to identify the first security algorithm.

[0107] In some embodiments of the second aspect, generating the fifth key based on the first security algorithm and the sixth key comprises one of: In some embodiments of the second aspect, the fourth information comprises algorithm identification information used to identify the first security algorithm.

[0108] generate the fifth key based on the sixth key, the algorithm identification information, a length of the algorithm identification information, the algorithm type information, and a length of the algorithm type information.

[0109] generate the fifth key based on the sixth key, the algorithm identification information, a length of the algorithm identification information, the algorithm type information, and a length of the algorithm type information.

[0110] In some embodiments of the second aspect, the sending, by the first node, the second message to the terminal comprises:

[0111] performing integrity protection on the second message using the fifth key, the second message comprising at least one of: the fourth information; the second information.

[0112] sending, by the first node, the second message to the terminal.

[0113] In some embodiments of the second aspect, the method further comprises:

[0114] receiving an indication of completion of the first security algorithm negotiation sent by the first node, the indication of completion of the first security algorithm negotiation being protected by a second key, the second key being used to protect communication security between the terminal and a second node.

[0115] sending, by the first node, a third message to the terminal, the third message being a response message to the first message, the third message being protected by the fifth key.

[0116] In a third aspect, the embodiments of the present disclosure provide a data security processing method, wherein the method is performed by a third node, and the method comprises: generating a sixth key according to a third key of the third node; and sending the sixth key to a second node, the sixth key being used by the second node to generate a fifth key, the fifth key being used to protect communication security between the second node and a terminal.

[0117] In the above embodiments, the third node generates the sixth key based on the third key, and sends the generated sixth key to the second node; since the sixth key is an intermediate key for generating the fifth key, it is beneficial for the second node to be able to generate the fifth key based on the sixth key, and to use the fifth key to protect the communication security between the second node and the terminal. In this way, the terminal is allowed to directly communicate with the second node in addition to directly communicating with the third node.

[0118] In some embodiments of the third aspect, the generating the sixth key according to the third key of the third node comprises:

[0119] receive an eighth message sent by the first node; the eighth message comprises a first message, the first message is protected by a fourth key; the fourth key is used to protect security of communication between the terminal and the third node;

[0120] decode the first message by using the fourth key;

[0121] generate the sixth key based on the third key and the decoded first message.

[0122] In some embodiments of the third aspect, the first message comprises at least one of the following: NAS signaling; an identity ID of the terminal; a first count value, the first count value is used to indicate a number of uplink messages sent by the terminal to the second node.

[0123] In some embodiments of the third aspect, the eighth message further comprises at least one of the following: type information of the second node; an instance ID of the second node.

[0124] In some embodiments of the third aspect, before generating the sixth key, the method further comprises at least one of the following:

[0125] determine the second node according to the type information of the second node;

[0126] determine the second node according to the instance ID of the second node;

[0127] determine the second node according to the message type of the first message;

[0128] determine the second node according to the information content of the first message.

[0129] In some embodiments of the third aspect, the sending the sixth key to the second node comprises:

[0130] send a fourth message to the second node, the fourth message comprises at least one of the following: the first message decoded based on the fourth key; the sixth key; second information used to indicate a first capability of the terminal, the first capability is related to security; identity information of the first node; address information of the first node.

[0131] In some embodiments of the third aspect, the generating the sixth key according to the third key of the third node comprises:

[0132] receive a sixth message sent by the second node, the sixth message is used to request the third node to generate the sixth key for the second node;

[0133] generate the sixth key based on the third key and the sixth message.

[0134] In some embodiments of the third aspect, the sixth message comprises at least one of: a terminal ID; and a first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node.

[0135] In some embodiments of the third aspect, the sending the sixth key to the second node comprises:

[0136] sending a seventh message to the second node, the seventh message comprising the sixth key.

[0137] In some embodiments of the third aspect, the generating the sixth key according to the third key of the third node comprises at least one of:

[0138] generating the sixth key according to the third key, a type of the second node, and a first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node;

[0139] generating the sixth key according to the third key, an instance ID of the second node, and the first count value.

[0140] In a fourth aspect, the embodiments of the present disclosure provide a data security processing method, wherein the method is performed by a first node, and the method comprises: receiving a first message sent by a terminal; sending the first message to a second node or a third node, the first message being used to enable the second node to determine a first security algorithm; receiving a second message sent by the second node; and sending the second message to the terminal, the second message being used to enable the terminal to determine the first security algorithm; the first security algorithm being used to enable the terminal to generate a second key, the second key being used to protect security of communication between the terminal and the second node.

[0141] In the above embodiments, after receiving the first message sent by the terminal, the first node directly sends the first message to the second node or sends the first message to the second node via the third node, so as to enable the second node to determine the first security algorithm by using the first message. The second message sent by the second node is forwarded to the terminal, so as to enable the terminal to learn the first security algorithm selected by the second node, thereby realizing security algorithm negotiation between the terminal and the second node. In this way, it is beneficial for the terminal and the second node to generate a security key between the terminal and the second node based on the first security algorithm, and to improve security of communication between the terminal and the second node.

[0142] In some embodiments of the fourth aspect, the receiving the first message sent by the terminal comprises at least one of:

[0143] receiving a first RRC message sent by the terminal, the first RRC message comprising the first message protected by a fourth key, the fourth key being used to protect a communication security between the terminal and the third node;

[0144] receiving a second RRC message sent by the terminal, the second RRC message comprising the first message unprotected by the fourth key.

[0145] In some embodiments of the fourth aspect, the first RRC message comprises at least one of: a first indicator indicating a message type of the first message; a second indicator indicating that the first node forwards the first message to a third node; type information of the second node; an instance ID of the second node.

[0146] In some embodiments of the fourth aspect, the third node sending the first message comprises:

[0147] sending, to a third node, an eighth message according to the first indicator or the second indicator in the first RRC message, the eighth message comprising the first message.

[0148] In some embodiments of the fourth aspect, the second RRC message comprises at least one of: a first indicator indicating a message type of the first message; type information of the second node; an instance ID of the second node.

[0149] In some embodiments of the fourth aspect, the first node sending the first message to the second node comprises:

[0150] sending, to the second node, a fifth message according to the type information of the second node and / or the instance ID of the second node in the second RRC message, the fifth message comprising at least one of: the first message unprotected; second information indicating a first capability of the terminal, the first capability being related to security.

[0151] In some embodiments of the fourth aspect, the first node sending the second message to the terminal comprises:

[0152] sending, to the terminal, a third RRC message, the third RRC message comprising the second message, the second message being integrity protected by a fifth key, the fifth key being generated according to a sixth key and the first security algorithm, the fifth key being used to protect a communication security between the second node and the terminal.

[0153] In some embodiments of the fourth aspect, the method further comprises:

[0154] receiving a fourth RRC message sent by the terminal, the fourth RRC message comprising an indication that the first security algorithm negotiation is completed;

[0155] sending, to the second node, an indication that the first security algorithm negotiation is completed. In some embodiments of the fourth aspect, the method further comprises:

[0156] receiving a third message sent by the second node, the third message being protected by a fifth key; the third message being a response message of the first message;

[0157] sending, to the terminal, a fifth RRC message, the fifth RRC message comprising the third message.

[0158] In a fifth aspect, the embodiments of the present disclosure provide a data security processing method, wherein the method is performed by a communication system, and the method comprises: a terminal sending a first message to a first node; the first node sending the first message to a second node or a third node; the first message being used for the second node to determine a first security algorithm; the third node generating a sixth key according to a third key of the third node; the third node sending the sixth key to the second node; the second node generating a fifth key based on the first security algorithm and the sixth key, the fifth key being used for protecting communication security between the second node and the terminal; the second node sending a second message to the first node; the first node sending the second message to the terminal; the second message being used for the terminal to determine the first security algorithm; the terminal generating a second key based on the first security algorithm and a first key; the second key being used for protecting communication security between the terminal and the second node; the first key being generated according to the third key of the third node.

[0159] In a sixth aspect, the embodiments of the present disclosure provide a terminal, wherein the terminal comprises: a sending module configured to send a first message to a first node, the first message being used for a second node to determine a first security algorithm; a receiving module configured to receive a second message sent by the first node; the second message being provided by the second node and the second message being used for the terminal to determine the first security algorithm; and a processing module configured to generate a second key based on the first security algorithm and a first key; the second key being used for protecting communication security between the terminal and the second node; the first key being generated according to a third key of a third node.

[0160] In a seventh aspect, an embodiment of the present disclosure provides a second node, where the second node includes: a receiving module configured to receive a first message sent by a first node or a third node, the first message being used for the second node to determine a first security algorithm; a processing module configured to generate a fifth key based on the first security algorithm and a sixth key, the fifth key being used to protect communication security between the second node and a terminal; the sixth key being generated according to a third key of the third node; and a sending module configured to send a second message to the terminal through the first node, the second message being used for the terminal to determine the first security algorithm.

[0161] In an eighth aspect, an embodiment of the present disclosure provides a third node, where the third node includes: a processing module configured to generate a sixth key according to a third key of the third node; and a sending module configured to send the sixth key to a second node, the sixth key being used by the second node to generate a fifth key, the fifth key being used to protect communication security between the second node and a terminal.

[0162] In a ninth aspect, an embodiment of the present disclosure provides a first node, where the first node includes: a receiving module configured to receive a first message sent by a terminal; and a sending module configured to send the first message to a second node or a third node, the first message being used for the second node to determine a first security algorithm; the receiving module is further configured to receive a second message sent by the second node; and the sending module is further configured to send the second message to the terminal, the second message being used for the terminal to determine the first security algorithm; the first security algorithm being used by the terminal to generate a second key, the second key being used to protect communication security between the terminal and the second node.

[0163] In a tenth aspect, an embodiment of the present disclosure provides a communication system, where the communication system includes a terminal, a first node, a second node, and a third node, the terminal is configured to implement the data security processing method provided in the first aspect, the second node is configured to implement the data security processing method provided in the second aspect, the third node is configured to implement the data security processing method provided in the third aspect, and the first node is configured to implement the data security processing method provided in the fourth aspect.

[0164] In an eleventh aspect, an embodiment of the present disclosure provides a communication device, where the communication device includes:

[0165] one or more processors;

[0166] The processor is configured to invoke instructions to cause the communication device to perform the data security processing method provided in the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0167] In a twelfth aspect, the embodiments of the present disclosure provide a storage medium, wherein the storage medium stores instructions, when the instructions are executed on a communication device, the communication device executes the data security processing method provided in the first aspect, the second aspect, the third aspect or the fourth aspect.

[0168] In a thirteenth aspect, the embodiments of the present disclosure provide a program product, wherein the program product comprises a program and / or instructions, when the program and / or instructions are executed by a communication device, the communication device can implement the data security processing method provided in the first aspect, the second aspect, the third aspect or the fourth aspect.

[0169] In a fourteenth aspect, the embodiments of the present disclosure provide a computer program, when the computer program is executed on a computer, the computer executes the data security processing method provided in the first aspect, the second aspect, the third aspect or the fourth aspect.

[0170] In a fifteenth aspect, the embodiments of the present disclosure provide a chip or a chip system. The chip or the chip system comprises processing circuitry configured to execute the data security processing method provided in the first aspect, the second aspect, the third aspect or the fourth aspect.

[0171] It can be understood that the terminal, the first node, the second node, the third node, the communication device, the communication system, the storage medium, the program product and the computer program are used to execute the method provided in the embodiments of the present disclosure. Therefore, the beneficial effects achieved by them can refer to the beneficial effects in the corresponding method, which will not be described here.

[0172] The embodiments of the present disclosure provide a data security processing method, a communication device, a communication system, a storage medium and a program product. In some embodiments, the data security processing method, the information processing method and the information transmission method can be replaced with each other, and the communication system and the information processing system can be replaced with each other.

[0173] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.

[0174] In the embodiments of the present disclosure, the terms and / or descriptions among the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0175] The terms used in the embodiments of the present disclosure are only for the purpose of describing particular embodiments and are not used as limitations of the present disclosure.

[0176] In the embodiments of the present disclosure, unless otherwise specified and logically conflicted, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this", etc., can represent "one and only one", or "one or more", "at least one", etc. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, or as plural expression.

[0177] In the embodiments of the present disclosure, "plurality" refers to two or more.

[0178] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.

[0179] In some embodiments, the writing methods such as "at least one of A, B", "A and / or B", "A in one case, B in another case", "one case A, another case B", and the like can include the following technical solutions according to the situation: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B are executed (A and B are executed). When there are more branches such as A, B, C, etc., it is similar to the above.

[0180] In some embodiments, the writing methods such as "A or B" and the like can include the following technical solutions according to the situation: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, etc., it is similar to the above.

[0181] The prefix words "first", "second", etc. in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments in the context of the description, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of "first field" and "second field". For another example, the description objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", where the quantity of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different. For example, the description objects are "devices", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different. For another example, the description objects are "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.

[0182] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0183] In some embodiments, the terms "time / frequency", "time / frequency domain" and the like refer to the time domain and / or the frequency domain.

[0184] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other. These descriptions all refer to the objective situation that the device will make corresponding processing, and are not limited by time. It is not required that the device has a judgment action when it is implemented, and it does not mean that there are other limitations.

[0185] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other. The terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0186] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "network function", "network device", "function", "node", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0187] In some embodiments, a "network" can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.

[0188] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like can be replaced with each other.

[0189] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0190] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.

[0191] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.

[0192] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country in which the location is situated.

[0193] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0194] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0195] FIG. 1A is a schematic diagram illustrating an architecture of a communication system according to an example embodiment.

[0196] As shown in FIG. 1A, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 can include an access network device and / or a core network device.

[0197] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a Pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, etc., but is not limited thereto.

[0198] In some embodiments, the terminal is also referred to as a user equipment (UE).

[0199] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a terminal to a wireless network, and the access network device may, for example, include at least one of an evolved node B (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.

[0200] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, at which time the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0201] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers are controlled by the CU, and the rest or all of the protocol layers are distributed in the DU and controlled by the CU, but is not limited thereto.

[0202] In some embodiments, the core network device can be one device including the first network element, etc., or can be multiple devices or device groups, each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0203] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0204] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subject, but are not limited thereto. The subjects shown in FIG. 1A are exemplary, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than FIG. 1A. The number and form of each subject is arbitrary, and the connection relationship between each subject is exemplary. Each subject can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0205] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).

[0206] In some embodiments, network functions (NFs) in the 6G architecture are streamlined in order to significantly improve performance in terms of capacity, coverage, signaling overhead, scalability, and energy consumption, etc. Dependencies between NFs can lead to unnecessary complexity and even delays. By redesigning network functions to reduce the number of dependencies and processing points. One way is: the possibility of direct signaling between enhanced NFs of the 6G system to eliminate potential bottlenecks. Today, many services need to pass information through a new generation radio access network (NG-RAN) node to a terminal device through a fifth generation mobile communication core network (5 th Generation Core, 5GC). In the 5GC, information is passed to the NG-RAN node through the access management function (AMF), and rarely needs to even need to involve the AMF. In order to simplify such transmission, the introduction of a service-based interface (SBI) for the NG-RAN will allow this information to be exchanged directly between the NG-RAN and the NF without going through the AMF, as shown in FIG. IB, which is a schematic diagram of a network architecture according to an example embodiment.

[0207] If the RAN evolves in the service direction, it means that the RAN node can be a consumer or producer that provides services for other network functions in addition to the AMF. In the 5th Generation (5G) system, only non-access layer (NAS) signaling is supported between the terminal and the AMF of the core network. Usually, NAS signaling is transparently transmitted through the RAN node. If the RAN can evolve to communicate directly with other core NFs without going through the AMF, it means that in addition to the AMF, NAS signaling also needs to be supported between the terminal and other core network NFs. Therefore, a 6G multi-NAS architecture can be enabled so that the RAN node can communicate directly with any NF through a service interface, and the terminal can use NAS signaling to communicate directly with any NF. As shown in FIGS. 1C and 1D, FIG. 1C is a schematic diagram of a 6G network architecture according to an example embodiment. FIG. 1D is a schematic diagram of a 6G network architecture according to an example embodiment.

[0208] However, the NAS security of the NAS signaling is only supported by the terminal and the AMF. As shown in FIG. 1E, which is a key hierarchy diagram in a 5G network according to an example embodiment. According to the key hierarchy shown in FIG. 1E, the root key (K AMF) derived by the terminal and a Security Anchor Function (SEAF). K AMF For the terminal and the AMF to derive a NAS integrity key K NASint and / or a NAS confidentiality protection key K NASenc , and no other core NF can derive the NAS security key. Since the current key hierarchy design of other core NFs does not support NAS security, the NAS signaling between the terminal and other core NFs cannot be protected. If the NAS signaling between the terminal and the NF is not protected, there is a risk that the NAS signaling information will be tampered with or eavesdropped when the RAN node forwarding the NAS signaling is attacked. Therefore, it is necessary to study how to protect the security of the 6G multi-NAS architecture.

[0209] In some embodiments, due to specific network deployment, each NF can support different security algorithms or the priority of the security algorithms supported by each NF is different. For example, the AMF only supports the Advanced Encryption Standard (AES), while the Location Management Function (LMF) only supports the byte stream encryption algorithm of the 3G communication system, such as SNOW 3G. For another example, the AMF and the LMF both support the same security algorithm, but the priority of the security algorithm in the AMF is configured as AES first and SNOW 3G second. While the priority of the security algorithm in the LMF is configured as SNOW 3G first and AES second. Therefore, due to the different capabilities of security algorithms of NFs or the different network configurations of the priority of security algorithms of NFs, the security algorithm negotiated between the terminal and the AMF cannot be used as the NAS security algorithm between the terminal and other NFs.

[0210] FIG. 2A is an interaction diagram I of a data security processing method according to an exemplary embodiment. As shown in FIG. 2A, the data security processing method according to the embodiments of the present disclosure is used for the communication system 100, and the method comprises:

[0211] In step S2101, the terminal generates a first key according to a third key of a third node.

[0212] The communication system can be the communication system shown in FIG. 1A. The terminal is the terminal 101 shown in FIG. 1A. The third node can be one of the network devices 102 shown in FIG. 1A. Exemplarily, the third node can be a core network node. In some embodiments, the third node can include but is not limited to an Access Management Function (AMF).

[0213] In some embodiments, the third node is an AMF, and the third key of the third node can be K AMF .

[0214] In some embodiments, the first key is an intermediate key for generating the second key.

[0215] In some embodiments, the second key is used to protect the communication security between the terminal and the second node. Illustratively, the second key is used to protect the NAS communication security between the terminal and the second node. Here, the NAS communication security can include the security of NAS messages.

[0216] In some embodiments, the first key is generated according to the third key and the type of the second node.

[0217] It should be noted that the second node can be one of the network devices 102 shown in FIG. 1A. In some embodiments, the second node can be any node in the terminal service network except the third node. Illustratively, the second node can be any core network node in the terminal service network except the third node. Also illustratively, the second node is not necessarily a core network node.

[0218] The terminal can determine the type of the second node according to the requested network service or function. For example, if the terminal requests a user name session, the type of the second node is a Session Management Function (SMF). If the terminal requests positioning, the type of the second node can be a Location Management Function (LMF).

[0219] In some embodiments, the terminal uses a Key Derivation Function (KDF) to derive the first key, with the third key as the input and the type of the second node as the derivation parameter.

[0220] In some other embodiments, the first key is generated according to the third key, a first count value, and the type of the second node; the first count value is used to indicate the number of uplink messages sent by the terminal to the second node.

[0221] Illustratively, the first count value can be the number of uplink NAS messages that have been sent by the terminal to the second node. If the terminal has not sent any uplink NAS message to the second node, the first count value can be 0.

[0222] In some embodiments, the first key is generated according to the third key and an instance identifier ID of the second node.

[0223] In some embodiments, the terminal can be pre-configured with an instance identity (ID) of the second node. In this case, the terminal can also generate the first key according to the instance ID of the second node and the third key.

[0224] In some embodiments, the first key is generated according to the third key, the first count value, and the instance ID of the second node.

[0225] In some embodiments, the terminal ID can also be used as a generation parameter of the first key when the first key is generated.

[0226] In this case, the first key is generated according to the third key in combination with one or more of the type of the second node, the instance ID of the second node, the first count value, and the terminal ID. If the first key is generated according to the terminal ID and the third key, the first keys corresponding to different terminals are different, thereby realizing isolation of the communication security between different terminals and the second node.

[0227] In some embodiments, the terminal ID can be any information capable of identifying the terminal. Exemplarily, the terminal ID can be the International Mobile Subscriber Identification Number (IMSI), the International Mobile Equipment Identity (IMEI), the 5G Globally Unique Temporary Identifier (GUTI), the Network Access Identifier (NAI), etc.

[0228] In step S2102, the terminal sends a first message to the first node.

[0229] In some embodiments, the first node receives the first message sent by the terminal.

[0230] In some embodiments, the first node can be an access network node, specifically various types of base stations.

[0231] In some embodiments, before the terminal sends the first message to the first node, the method further includes:

[0232] The first message is protected using the fourth key.

[0233] In some embodiments, the fourth key is used to protect the communication security between the terminal and the third node. Exemplarily, the fourth key is used to protect the NAS communication security between the terminal and the third node. Here, the NAS communication security can include the security of the NAS message.

[0234] It should be noted that, since the second node for the terminal to directly communicate is determined by the third node in the embodiments of the present disclosure, the first message needs to be forwarded to the second node via the third node. In this case, although the terminal does not establish the NAS security context between the terminal and the second node, the terminal can use the existing NAS security context between the terminal and the third node to protect the first message, i.e., use the fourth key to protect the first message, so as to improve the security of the first message.

[0235] In some embodiments, the terminal sends a first RRC message to the first node, and the first RRC message includes the first message.

[0236] It should be noted that, in the case that the first message needs to be forwarded to the second node via the first node and the third node in turn, the terminal sends the first RRC message carrying the first message to the first node.

[0237] It can be understood that the first message can be carried in the first RRC message in the form of a message container.

[0238] In some embodiments, in order to further improve the security of the first message, the first RRC message is protected using an access stratum (AS) security context. Exemplarily, the AS security context can include a key for the communication between the terminal and the access network node. For example, the first RRC message is encrypted and / or integrity protected.

[0239] In some embodiments, the first message includes at least one of the following: NAS signaling; an identity (ID) of the terminal; and a first count value.

[0240] In some embodiments, the NAS signaling can be a NAS message that the terminal needs to send to the second node. The NAS signaling can be carried in the first RRC message in the form of a container.

[0241] In some embodiments, the signaling content of the NAS signaling is different for different types of second nodes.

[0242] In some embodiments, the second node is an LMF, and the NAS signaling can be an encapsulated long term evolution (LTE) positioning protocol (LPP) NAS signaling, and / or the NAS signaling is related to the absolute positioning and / or relative positioning of the terminal.

[0243] In some embodiments, the second node is an SMF, and the signaling content of the NAS signaling is related to establishment, connection or release of a Protocol Data Unit (PDU).

[0244] In some embodiments, the ID of the terminal can include, but is not limited to, various types of IDs of the UE, such as IMEI, IMSI, or NAI, etc.

[0245] In some embodiments, the first count value is used to indicate the number of uplink messages sent by the terminal to the second node. For example, the first count value can be the number of uplink NAS messages that have been sent by the terminal to the second node. If the terminal has not sent any uplink NAS message to the second node, the first count value can be 0.

[0246] In some embodiments, the first RRC message includes at least one of the following: a first indicator used to indicate the message type of the first message; a second indicator used to indicate that the first node forwards the first message to the third node; type information of the second node; an instance ID of the second node; address information of the second node.

[0247] In some embodiments, the first indicator is also used to indicate the type of the NAS signaling in the first message.

[0248] In some embodiments, the first indicator is carried in the first RRC message, which can make the first node know the type of the first message and / or the NAS signaling, so that it can be determined whether the first message needs to be sent to the third node according to the type of the first message and / or the NAS signaling.

[0249] In some embodiments, the second indicator is carried in the first RRC message, which can make the first node determine that the first message needs to be sent to the third node.

[0250] In some embodiments, the type information of the second node is carried in the first RRC message, which can make the third node know the type of the second node, and select the second node for the terminal according to the location information of the terminal and / or the second node that can be reached by the first node.

[0251] In some embodiments, the instance ID of the second node can be an identifier of the second node pre-configured on the terminal, etc. In some embodiments, the terminal acquires the instance ID of the second node according to historical communication.

[0252] In some embodiments, the address information of the second node can include, but is not limited to, an Internet Protocol (IP) address.

[0253] In step S2103, the first node sends an eighth message to the third node.

[0254] In some embodiments, the third node receives the eighth message sent by the first node.

[0255] In some embodiments, the third node can be a core network function such as a SEAF or an AMF or a Mobile Manangement Entity (MME).

[0256] In some embodiments, the first node sends the eighth message to the third node, the eighth message can comprise the first message. It can be understood that the first node sends the received first message to the third node.

[0257] In some embodiments, the first node can only act as a forwarding node of the first message. Illustratively, the first node receives the first RRC message, extracts the first message from the first RRC message, and sends the eighth message comprising the first message to the third node.

[0258] In some embodiments, the eighth message comprising the first message is sent to the third node according to the first indicator or the second indicator in the first RRC message.

[0259] It should be noted that in the case that the first node receives the first RRC message, the first node needs to determine the receiving node of the first message in the first RRC message. If the first RRC message comprises the first indicator or the second indicator, the first node can determine that the third node is a forwarding node of the first message according to the first indicator or the second indicator; therefore, the first node sends the eighth message comprising the first message to the third node.

[0260] It can be understood that the first indicator is used to indicate the message type of the first message, and the first node determines the message type of the first message according to the first indicator, so as to determine whether to send the first message to the third node according to the message type of the first message.

[0261] The second indicator is used to indicate that the first node forwards the first message to the third node, and the first node can send the eighth message comprising the first message to the third node according to the second indicator.

[0262] In some embodiments, the first message is protected by a fourth key.

[0263] It should be noted that the fourth key is used to protect the communication security between the terminal and the third node. Illustratively, the fourth key is used to protect the NAS communication security between the terminal and the third node. Here, the NAS communication security can comprise the security of the NAS message.

[0264] In some embodiments, after the third node receives the eighth message sent by the first node, the method further comprises decoding the first message using the fourth key.

[0265] It can be understood that the fourth key is used to protect the security of the communication between the terminal and the third node. Illustratively, the fourth key includes a confidentiality key and an integrity key; the third node decodes the first message using the confidentiality key; and verifies the integrity of the first message using the integrity key.

[0266] In some embodiments, the eighth message further includes at least one of the following: type information of the second node; and an instance ID of the second node.

[0267] It should be noted that the RAN node can determine the second node by including the type information of the second node and / or the instance ID of the second node in the eighth message sent to the third node.

[0268] Step S2104, the third node determines the second node.

[0269] In some embodiments, the third node determines the second node for the terminal.

[0270] It should be noted that the third node determines the second node capable of directly communicating with the terminal for the terminal.

[0271] In some embodiments, the third node determines the second node for the terminal, including at least one of the following:

[0272] According to the type information of the second node, the second node is determined;

[0273] According to the instance ID of the second node, the second node is determined;

[0274] According to the message type of the first message, the second node is determined;

[0275] According to the information content of the first message, the second node is determined.

[0276] It can be understood that the third node can select the second node for the terminal according to the type information of the second node and / or the instance ID of the second node indicated by the first node. Alternatively, the third node can select the second node for the terminal according to the first message forwarded by the first node.

[0277] In some embodiments, the third node receives the type information of the second node, and selects the second node for the terminal according to the location information of the terminal and / or the load information of the second node.

[0278] Step S2105, the third node generates a sixth key according to the third key of the third node.

[0279] In some embodiments, the third node can be an AMF, and the third key of the third node can be K AMF .

[0280] In some embodiments, the sixth key is an intermediate key for generating the fifth key.

[0281] In some embodiments, the sixth key is generated according to the third key and type information of the second node.

[0282] It can be understood that, in the case that the first message comprises the type information of the second node or the third node indicates the type of the second node through the eighth message, the third node generates the sixth key according to the third key and the type information of the second node.

[0283] In some embodiments, the third node derives the sixth key using a Key Derivation Function (KDF) with the third key as input and the type information of the second node as derivation parameter.

[0284] In some embodiments, the sixth key is generated according to the third key and the instance ID of the second node.

[0285] It can be understood that, in the case that the first message comprises the instance ID of the second node or the third node indicates the instance ID of the second node through the eighth message, the third node generates the sixth key according to the third key and the instance ID of the second node.

[0286] In some embodiments, the sixth key is generated according to the third key, the first count value and the instance ID of the second node.

[0287] In some embodiments, the terminal ID can also be used as a generation parameter of the sixth key when the sixth key is generated.

[0288] In this case, the sixth key is generated according to the third key in combination with one or more of the type of the second node, the instance ID of the second node, the first count value and the terminal ID. If the sixth key is generated according to the terminal ID and the third key, the sixth keys corresponding to different terminals are different, thereby realizing isolation of communication security between different terminals and the second node.

[0289] In step S2106, the third node sends a fourth message to the second node.

[0290] In some embodiments, the second node receives the fourth message sent by the third node.

[0291] In some embodiments, the fourth message at least comprises the first message decoded based on the fourth key.

[0292] It should be noted that the receiving node of the first message is the second node; the third node decodes the first message using the fourth key and sends the decoded first message to the second node, so as to complete the transmission of the first message between the terminal and the second node.

[0293] In some embodiments, the fourth message comprises at least one of: the sixth key; second information, used to indicate the first capability of the terminal, the first capability being related to security; identification information of the first node; address information of the first node.

[0294] In some embodiments, the sixth key is used by the second node to generate the fifth key. It is to be noted that the sixth key is an intermediate key for generating the fifth key. The third node carries the sixth key in the fourth message, so that the second node generates the fifth key based on the sixth key.

[0295] In some embodiments, the second information is further used to indicate a security algorithm supported by the terminal.

[0296] In some embodiments, the second information is used by the second node to determine the first security algorithm.

[0297] It is to be noted that the first security algorithm is used by the second node to generate the fifth key. The third node carries the second information in the fourth message, so that the second node negotiates the security algorithm for the NAS communication between the second node and the terminal.

[0298] In some embodiments, the address information of the first node can include, but is not limited to, an IP address.

[0299] At step S2107, the second node determines the first security algorithm.

[0300] In some embodiments, after the second node receives the second information, the second node determines the first security algorithm.

[0301] In some embodiments, the first security algorithm is a security algorithm negotiated between the second node and the terminal.

[0302] In some embodiments, the second node determining the first security algorithm comprises: determining fourth information according to the second information and third information, the third information being used to indicate the first capability of the second node, and the fourth information being used to indicate the first security algorithm selected by the second node.

[0303] It is to be noted that after the second node receives the second information, the second node can select the first security algorithm according to the first capability of the second node itself and the first capability of the terminal.

[0304] It is to be noted that considering that the security algorithm supported by the second node and the security algorithm supported by the terminal can be different, or the security algorithm supported by the second node and the security algorithm supported by the terminal are the same but the priority configuration of the security algorithm of the second node and the priority configuration of the security algorithm of the terminal are different, in the embodiments of the present disclosure, the first security algorithm needs to be determined before the second node generates the fifth key.

[0305] In some embodiments, the fourth information comprises: algorithm identification information, used to identify the first security algorithm.

[0306] At step S2108, the second node generates a fifth key based on the first security algorithm and the sixth key.

[0307] In some embodiments, the fifth key is used to protect the communication between the second node and the terminal.

[0308] It should be noted that in the case where the second node communicates directly with the terminal without forwarding via the third node, in order to ensure the security of the communication between the second node and the terminal, the second node can generate a fifth key based on the first security algorithm and the sixth key, and use the fifth key to protect the message sent by the second node to the terminal.

[0309] In some embodiments, generating the fifth key based on the first security algorithm and the sixth key comprises at least one of:

[0310] generating the fifth key based on the sixth key and the algorithm identification information;

[0311] generating the fifth key based on the sixth key, the algorithm identification information and the length of the algorithm identification information.

[0312] In some embodiments, the second node uses a KDF to derive the fifth key with the sixth key as input and the algorithm identification information as derivation parameter.

[0313] In some embodiments, the second node uses a KDF to derive the fifth key with the sixth key as input and the algorithm identification information and the length of the algorithm identification information as derivation parameter.

[0314] In some embodiments, generating the fifth key based on the sixth key, the algorithm identification information and the algorithm type information.

[0315] In some embodiments, generating the fifth key based on the sixth key, the algorithm identification information, the length of the algorithm identification information, the algorithm type information and the length of the algorithm type information.

[0316] In some embodiments, the algorithm type information is used to indicate the type of the first security algorithm.

[0317] In some embodiments, the fifth key is generated with the sixth key as input of the KDF and in combination with one or more of the following parameters:

[0318] P0 = algorithm type distinguisher, exemplary types of the security algorithm herein include but are not limited to integrity algorithm and / or confidentiality algorithm;

[0319] L0 = length of P0;

[0320] P1 = security algorithm ID; exemplary, ID for AES (Advanced Encryption Standard), ID for ZUC (Zuluo's algorithm), etc.

[0321] L1 = length of algorithm ID.

[0322] At step S2109, the second node sends the second message to the first node.

[0323] In some embodiments, the second node sending the second message to the first node comprises at least one of:

[0324] The fourth message comprises the identification information of the first node and / or the address information of the first node, and the second message is sent to the first node.

[0325] The fourth message does not comprise the identification information of the first node and the address information of the first node, and the second message is sent to the first node via the third node.

[0326] It can be understood that, in the case that the fourth message received by the second node comprises the identification information of the first node and / or the address information of the first node, the second message can be directly sent to the first node by the second node. In the case that the fourth message received by the second node does not comprise the identification information of the first node and the address information of the first node, the second message needs to be sent to the first node via the third node.

[0327] In some embodiments, the second message is used by the terminal to determine the first security algorithm. It should be noted that the first node is a forwarding node of the second message, and the terminal is a receiving node of the second message. The second node sends the second message to the first node, so that the first node forwards the second message to the terminal, so that the terminal determines the first security algorithm according to the second message, thereby generating the second key.

[0328] In some embodiments, sending the second message to the first node comprises: integrity protecting the second message using the fifth key; and sending the second message to the first node.

[0329] It can be understood that, before sending the second message, the second node can integrity protect the second message using the fifth key, so that the terminal, after generating the second key based on the second message, verifies the integrity of the second message using the second key, to verify the establishment of the shared security context between the terminal and the second node; and improve the success of establishing the shared security context between the terminal and the second node.

[0330] In some embodiments, the second message comprises at least one of: the fourth information; and the second information.

[0331] In some embodiments, the fourth information comprises: algorithm identification information, used to identify the first security algorithm.

[0332] It is to be noted that the second node informs the terminal of the first security algorithm selected by the second node by including the algorithm identification information in the second message, so as to complete the security algorithm negotiation between the second node and the terminal.

[0333] In some embodiments, the second information is used to indicate a first capability of the terminal related to security.

[0334] In some embodiments, the second message can be a NAS Security Mode Command (SMC) message.

[0335] At step S2110, the first node sends a second message to the terminal.

[0336] In some embodiments, the second message is integrity protected by a fifth key.

[0337] In some embodiments, the first node sending the second message to the terminal comprises: sending a third RRC message to the terminal, the third RRC message comprising the second message.

[0338] It can be understood that the first node can encapsulate the integrity-protected second message in the third RRC message and send it to the terminal.

[0339] In some embodiments, in order to improve the security of the second message, the third RRC message is protected using an AS security context. Illustratively, the AS security context can comprise a key for communication between the terminal and the access network node. For example, the third RRC message is encrypted and / or integrity protected.

[0340] In some embodiments, the second message comprises at least one of: algorithm identification information, used to identify the first security algorithm; and the second information, used to indicate a first capability of the terminal, the first capability being related to security.

[0341] In some embodiments, the method further comprises: storing, by the first node, identification information of the second node and / or address information of the second node in a context of the terminal.

[0342] It can be understood that, by storing the identification information of the second node and / or the address information of the second node in the context of the terminal, the first node enables the terminal to directly forward messages via the first node when communicating with the second node in the future, without the need to forward messages via the third node again.

[0343] The terminal determines the first security algorithm in step S2111.

[0344] In some embodiments, the first security algorithm is a security algorithm negotiated between the second node and the terminal.

[0345] In some embodiments, the terminal determining the first security algorithm comprises: determining the first security algorithm according to the algorithm identification information in the second message.

[0346] It should be noted that the terminal determines the first security algorithm selected by the second node according to the algorithm identification information in the second message. Considering that the security algorithms supported by the second node and the security algorithms supported by the terminal can be different, or the security algorithms supported by the second node and the security algorithms supported by the terminal are the same but the priority configuration of the security algorithms of the second node is different from the priority configuration of the security algorithms of the terminal. Therefore, the second node selects the first security algorithm based on the first capability of the second node and the first capability of the terminal; and informs the terminal of the selected first security algorithm through the second message, so that the terminal generates a second key based on the first security algorithm.

[0347] The terminal generates a second key based on the first security algorithm and the first key in step S2112.

[0348] In some embodiments, the second key is used to protect the security of communication between the terminal and the second node.

[0349] It should be noted that in the case where the second node directly communicates with the terminal without forwarding via the third node, in order to ensure the security of communication between the terminal and the second node, the terminal can generate a second key based on the first security algorithm and the first key, and use the second key to protect the message sent by the terminal to the second node.

[0350] In some embodiments, generating the second key based on the first security algorithm and the first key comprises at least one of:

[0351] generating the second key based on the first key and the algorithm identification information;

[0352] generating the second key based on the first key, the algorithm identification information and the length of the algorithm identification information.

[0353] In some embodiments, the terminal uses the KDF to derive the second key with the first key as input and the algorithm identification information as derivation parameter.

[0354] In some embodiments, the terminal uses the KDF to derive the second key with the first key as input and the algorithm identification information and the length of the algorithm identification information as derivation parameter.

[0355] In some embodiments, the second key is generated based on the first key, the algorithm identification information and the algorithm type information.

[0356] In some embodiments, the second key is generated based on the first key, the algorithm identification information, a length of the algorithm identification information, the algorithm type information, and a length of the algorithm type information.

[0357] In some embodiments, the algorithm type information is used to indicate a type of the first security algorithm.

[0358] In some embodiments, the second key is generated with the first key as an input of the KDF, and in combination with one or more of the following parameters:

[0359] P0 = an algorithm type distinguisher; exemplary types of the security algorithm herein include, but are not limited to, an integrity algorithm and / or a confidentiality algorithm;

[0360] L0 = a length of P0;

[0361] P1 = a security algorithm ID; exemplary IDs include an ID for an Advanced Encryption Standard (AES), an ID for ZUC, etc.

[0362] L1 = a length of the algorithm ID.

[0363] In some embodiments, the second key includes at least one of a confidentiality key and an integrity key.

[0364] In some embodiments, the method further includes: performing, by the terminal, integrity verification on the second message using the second key.

[0365] It can be understood that, after generating the second key, the terminal can perform integrity verification on the second message that is integrity-protected by the fifth key using the second key; thereby verifying the establishment of the shared security context between the terminal and the second node by using the second key to perform integrity verification on the second message; and improving the success of establishing the shared security context between the terminal and the second node.

[0366] At step S2113, the terminal sends an indication of completion of the first security algorithm negotiation to the first node.

[0367] In some embodiments, the terminal sending the indication of completion of the first security algorithm negotiation to the first node includes: sending, to the first node, a fourth RRC message including the indication of completion of the first security algorithm negotiation; and the fourth RRC message being protected using the second key.

[0368] In some embodiments, the second node is a receiving node of the indication of the completion of the first security algorithm negotiation. It is to be understood that the terminal sends the indication of the completion of the first security algorithm negotiation to the first node, so that the first node forwards the indication to the second node.

[0369] In some embodiments, the first RRC message can comprise all message contents of the initial NAS message.

[0370] Step S2114, the first node sends an indication of the completion of the first security algorithm negotiation to the second node.

[0371] In some embodiments, the second node is a receiving node of the indication of the completion of the first security algorithm negotiation. It is to be understood that the first node can forward the received indication to the second node.

[0372] In some embodiments, the second node decodes and verifies the received indication using the fifth key.

[0373] Step S2115, the second node sends a third message to the first node.

[0374] In some embodiments, the third message is a response message of the first message.

[0375] In some embodiments, the first message comprises a NAS request, and the third message is a response message of the NAS request.

[0376] It is to be understood that the first message sent by the terminal can comprise a NAS request, and the second node does not respond to the NAS request in the case that the first security algorithm negotiation is not completed. After the first node sends the indication of the completion of the first security algorithm negotiation to the second node, the second node sends a response message of the NAS request to the terminal through the first node.

[0377] In some embodiments, the second node sending the third message to the first node comprises: protecting the third message using the fifth key, and sending the third message to the first node.

[0378] It is to be understood that the second node can send the third message to the first node in response to the first message after receiving the first message, and the third message is protected by the fifth key.

[0379] Step S2116, the first node sends the third message to the terminal.

[0380] In some embodiments, the third message is a response message of the first message.

[0381] In some embodiments, the first node sending the third message to the terminal comprises: sending a fifth RRC message to the terminal, the fifth RRC message comprising the third message, and the third message being protected by the fifth key.

[0382] It should be noted that the first node can encapsulate the received third message in a fifth RRC message, and send the third message to the terminal by sending the fifth RRC message to the terminal.

[0383] In some embodiments, the term "information" can be mutually replaced with the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.

[0384] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be mutually replaced, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like. The protocol, for example, includes at least one of a 3GPP protocol, a Wi-Fi protocol, an audio and / or video protocol.

[0385] In some embodiments, the term "send" can be mutually replaced with the terms "transmit", "report", "transmit", and the like.

[0386] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S2101-S2116. For example, steps S2101-S2112 can be implemented as an independent embodiment, and steps S2101-S2103 can be implemented as an independent embodiment, but are not limited thereto.

[0387] In some embodiments, steps S2113-S2116 can all be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S2113-S2116.

[0388] In some embodiments, steps S2104 to S2116 can all be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need for the terminal to communicate with the second node, and thus there is no need to perform steps S2113 to S2116. For example, although the terminal generates the first key and sends the first message, in the case that no suitable second node is selected for the terminal, or the second node selected for the terminal refuses to communicate with the terminal, the third node does not need to generate the sixth key, and does not need to send the fourth message.

[0389] In some embodiments, other optional implementations can be described before or after the description of Figure 2A.

[0390] Figure 2B is a second interaction diagram illustrating a data security processing method according to an example embodiment. As shown in Figure 2B, the embodiments of the present disclosure relate to a data security processing method, for a communication system 100, the method comprising:

[0391] Step S2201: The terminal generates a first key according to a third key of a third node.

[0392] The communication system can be the communication system shown in Figure 1A. The terminal is the terminal 101 shown in Figure 1A. The third node can be one of the network devices 102 shown in Figure 1A. For example, the third node can be a core network node. In some embodiments, the third node can include but is not limited to an AMF.

[0393] In some embodiments, the third node is an AMF, and the third key of the third node can be K AMF .

[0394] In some embodiments, the first key is an intermediate key for generating the second key.

[0395] In some embodiments, the second key is used to protect the security of communication between the terminal and the second node. For example, the second key is used to protect the security of NAS communication between the terminal and the second node. Here, the security of NAS communication can include the security of NAS messages.

[0396] In some embodiments, the first key is generated according to the third key and the type of the second node.

[0397] It should be noted that the second node can be one of the network devices 102 shown in Figure 1A. In some embodiments, the second node can be any node in the terminal service network other than the third node. For example, the second node can be any core network node in the terminal service network other than the third node. For another example, the second node does not necessarily have to be a core network node.

[0398] The terminal can determine the type of the second node according to the requested network service or function. For example, the terminal requests a username session, and the type of the second node is SMF. The terminal requests positioning, and the type of the second node can be LMF.

[0399] In some embodiments, the terminal uses a KDF to derive the first key, taking the third key as input and taking the type of the second node as a derivation parameter.

[0400] In some other embodiments, the first key is generated according to the third key, a first count value, and the type of the second node; the first count value is used to indicate the number of uplink messages sent by the terminal to the second node.

[0401] Exemplarily, the first count value can be the number of uplink NAS messages that the terminal has sent to the second node. If the terminal has not sent any uplink NAS message to the second node, the first count value can be 0.

[0402] In some embodiments, the first key is generated according to the third key and the instance ID of the second node.

[0403] In some embodiments, the terminal can be pre-configured with the instance ID of the corresponding second node. In this case, the terminal can also generate the first key according to the instance ID of the second node and the third key.

[0404] In some embodiments, the first key is generated according to the third key, the first count value, and the instance ID of the second node.

[0405] In some embodiments, the terminal ID can also be used as a generation parameter of the first key when the first key is generated.

[0406] In this case, the first key is generated according to the third key in combination with one or more of the type of the second node, the instance ID of the second node, the first count value, and the terminal ID. If the first key is generated according to the terminal ID and the third key, the first keys corresponding to different terminals are different, thereby realizing isolation of the communication security between different terminals and the second node.

[0407] In some embodiments, the terminal ID can be any information capable of identifying the terminal. Exemplarily, IMSI, IMEI, GUTI, NAI, etc. can be unique terminal information.

[0408] Step S2202: The terminal sends a first message to the first node.

[0409] In some embodiments, the first node can be an access network node, specifically various types of base stations.

[0410] In some embodiments, the first message is not protected by the fourth key.

[0411] It should be noted that, since the second node for direct communication of the terminal is not determined by the third node in the embodiments of the present disclosure, the first message does not need to be forwarded to the second node via the third node. In this case, since the terminal does not establish a security context between the terminal and the second node, the terminal cannot protect the first message by the security context between the terminal and the second node.

[0412] In some embodiments, the first message at least includes a first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node.

[0413] It should be noted that, since the first message is not protected by the fourth key, the first message can only carry information that does not need to be protected and information necessary for negotiating a security algorithm, including the first count value.

[0414] In some embodiments, the first count value is a count of uplink NAS messages sent by the terminal to the second node. Exemplarily, the first count value can be a number of uplink NAS messages that have been sent by the terminal to the second node. If the terminal has not sent any uplink NAS message to the second node, the first count value can be 0.

[0415] In some embodiments, the terminal sends a second RRC message to the first node, the second RRC message including the first message that is not protected by the fourth key.

[0416] It should be noted that, in the case where the first message needs to be forwarded to the second node via the first node, the terminal sends a second RRC message carrying the first message to the first node.

[0417] It can be understood that the first message can be carried in the second RRC message in the form of a message container.

[0418] In some embodiments, in order to improve the security of the first message, the second RRC message is protected using an access layer AS security context. Exemplarily, the AS security context can include a key for communication between the terminal and the access network node. For example, the second RRC message is encrypted and / or integrity protected.

[0419] In some embodiments, the second RRC message further includes at least one of the following: a first indicator indicating a message type of the first message; type information of the second node; an instance ID of the second node; address information of the second node.

[0420] In some embodiments, the type information of the second node is carried in the second RRC message, which can make the first node know the type of the second node, and the second node can be selected for the UE according to the location information of the terminal and / or the second node reachable by the first node.

[0421] In some embodiments, the instance ID of the second node can be an identifier of the second node pre-configured on the terminal, and the like. In some embodiments, the instance ID of the second node is acquired by the terminal according to historical communication.

[0422] In some embodiments, the address information of the second node can include, but is not limited to, an Internet Protocol (IP) address.

[0423] In step S2203, the first node sends a fifth message to the second node.

[0424] In some embodiments, the first node sends the fifth message to the second node, and the fifth message includes the unprotected first message. It can be understood that the first node sends the received unprotected first message to the second node.

[0425] In some embodiments, the first node can only act as a forwarding node of the first message. For example, the first node receives the second RRC message, extracts the first message from the second RRC message, and sends the fifth message including the first message to the second node.

[0426] In some embodiments, the second node is a receiving node of the first message. It can be understood that the first message in the embodiments of the present disclosure is directly sent by the first node to the second node without being sent to the second node through the third node.

[0427] In some embodiments, the fifth message is sent to the second node according to the type information of the second node or the instance ID of the second node in the second RRC message.

[0428] It should be noted that in the case that the first node receives the second RRC message, the first node needs to determine the receiving node of the first message in the second RRC message. If the type information of the second node or the instance ID of the second node is included in the second RRC message, the first node can determine that the second node is the receiving node of the first message according to the type information of the second node or the instance ID of the second node; therefore, the first node sends the fifth message including the first message to the second node.

[0429] In step S2204, the second node sends a sixth message to the third node.

[0430] In some embodiments, after the second node receives the first message, the second node sends the sixth message to the third node.

[0431] In some embodiments, the sixth message is used to request the third node to generate a sixth key for the second node.

[0432] In some embodiments, the sixth key is an intermediate key for generating the fifth key.

[0433] In some embodiments, the sixth message can be a key generation request.

[0434] In some embodiments, the sixth message comprises at least one of: a terminal ID; a first count value.

[0435] In some embodiments, the second node can obtain the terminal ID based on the first message, or the second node can obtain the terminal ID from the first node.

[0436] It should be noted that, in the case that the first message comprises the terminal ID, the second node can obtain the terminal ID based on the first message; in the case that the first message does not comprise the terminal ID, the second node can obtain the terminal ID from the first node through IP mapping.

[0437] In some embodiments, the second node can obtain the first count value based on the first message.

[0438] In some embodiments, the sixth message can further comprise at least one of: type information of the second node; an instance ID of the second node.

[0439] In step S2205, the third node generates a sixth key according to a third key of the third node.

[0440] In some embodiments, the third node can be an AMF, and the third key of the third node can be K AMF .

[0441] In some embodiments, the sixth key is generated according to the third key and the type information of the second node.

[0442] It can be understood that, in the case that the sixth message comprises the instance ID of the second node, the third node can generate the sixth key according to the third key and the type information of the second node.

[0443] In some embodiments, the third node uses a key derivation function (KDF) to derive the sixth key, taking the third key as input and taking the type information of the second node as derivation parameters.

[0444] In some embodiments, the sixth key is generated according to the third key and the instance ID of the second node.

[0445] It can be understood that, in the case that the sixth message comprises the instance ID of the second node, the third node generates the sixth key according to the third key and the instance ID of the second node.

[0446] In some embodiments, the sixth key is generated according to the third key, the first count value, and the instance ID of the second node.

[0447] In some embodiments, the terminal ID can also be used as a generation parameter of the sixth key when the sixth key is generated.

[0448] In this case, the sixth key is generated according to the third key and in combination with one or more of the type of the second node, the instance ID of the second node, the first count value, and the terminal ID. If the sixth key is generated according to the terminal ID and the third key, the sixth keys corresponding to different terminals are different, thereby realizing isolation of the communication security between different terminals and the second node.

[0449] In step S2206, the third node sends a seventh message to the second node.

[0450] In some embodiments, the seventh message can include the sixth key. It should be noted that the third node can send the seventh message to the second node after generating the sixth key, so as to send the generated sixth key to the second node through the seventh message, so that the second node generates the fifth key based on the sixth key.

[0451] In some embodiments, the third node can be an AMF, and the seventh message further includes second information.

[0452] It should be noted that in the case where the third node is an AMF, the third node can retrieve the second information based on the context of the terminal, so as to send the second information to the second node through the seventh message, so that the second node determines the first security algorithm according to the second information.

[0453] In step S2207, the second node determines the first security algorithm.

[0454] In some embodiments, the optional implementation of the second node determining the first security algorithm can be referred to the related description in the corresponding embodiment S2107 of FIG. 2A.

[0455] In step S2208, the second node generates the fifth key based on the first security algorithm and the sixth key.

[0456] In some embodiments, the optional implementation of the second node generating the fifth key based on the first security algorithm and the sixth key can be referred to the related description in the corresponding embodiment S2108 of FIG. 2A.

[0457] In step S2209, the second node sends a second message to the first node.

[0458] In some embodiments, the second message is used for the terminal to determine the first security algorithm. It should be noted that the first node is a forwarding node of the second message, and the terminal is a receiving node of the second message. The second node sends the second message to the first node, so that the first node forwards the second message to the terminal, so that the terminal determines the first security algorithm according to the second message, thereby generating the second key.

[0459] In some embodiments, sending the second message to the first node comprises: integrity protecting the second message using the fifth key; and sending the second message to the first node.

[0460] It can be understood that, before sending the second message, the second node can integrity protect the second message using the fifth key, so that the terminal verifies the establishment of the shared security context between the terminal and the second node by verifying the integrity of the second message using the second key after generating the second key based on the second message; and improves the success of establishing the shared security context between the terminal and the second node.

[0461] In some embodiments, the second message comprises at least one of: the fourth information; and the second information.

[0462] In some embodiments, the fourth information comprises: algorithm identification information, used to identify the first security algorithm.

[0463] It should be noted that the second node informs the terminal of the first security algorithm selected by the second node by including the algorithm identification information in the second message, so as to complete the security algorithm negotiation between the second node and the terminal.

[0464] In some embodiments, the second information is used to indicate the first capability of the replayed terminal.

[0465] In some embodiments, the second message can be a NAS security mode command (SMC) message.

[0466] Step S2210: The first node sends a second message to the terminal.

[0467] In some embodiments, the optional implementation of the first node sending the second message to the terminal can be referred to the related description in the corresponding embodiment S2110 of FIG. 2A.

[0468] Step S2211: The terminal determines the first security algorithm.

[0469] In some embodiments, the optional implementation of the terminal determining the first security algorithm can be referred to the related description in the corresponding embodiment S2111 of FIG. 2A.

[0470] Step S2212: The terminal generates a second key based on the first security algorithm and the first key.

[0471] In some embodiments, the optional implementation of the terminal generating the second key based on the first security algorithm and the first key can be referred to the related description in the corresponding embodiment S2112 of FIG. 2A.

[0472] Step S2213, the terminal sends an indication of completion of the first security algorithm negotiation to the first node.

[0473] In some embodiments, the optional implementation of the terminal sending the indication of completion of the first security algorithm negotiation to the first node can be referred to the related description in the corresponding embodiment S2113 of FIG. 2A.

[0474] Step S2214, the first node sends an indication of completion of the first security algorithm negotiation to the second node.

[0475] In some embodiments, the optional implementation of the first node sending the indication of completion of the first security algorithm negotiation to the second node can be referred to the related description in the corresponding embodiment S2114 of FIG. 2A.

[0476] Step S2215, the second node sends a third message to the first node.

[0477] In some embodiments, the optional implementation of the second node sending the third message to the first node can be referred to the related description in the corresponding embodiment S2115 of FIG. 2A.

[0478] Step S2216, the first node sends the third message to the terminal.

[0479] In some embodiments, the optional implementation of the first node sending the third message to the terminal can be referred to the related description in the corresponding embodiment S2116 of FIG. 2A.

[0480] In some embodiments, the term “information” can be mutually replaced with the terms “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “field”, “data”, and the like.

[0481] In some embodiments, “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive” can be mutually replaced, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like. The protocols include at least one of 3GPP protocols, Wi-Fi protocols, audio and / or video protocols, and the like.

[0482] In some embodiments, the term “send” can be mutually replaced with the terms “transmit”, “report”, “transmit”, and the like.

[0483] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S2201-S2216. For example, steps S2201-S2212 can be implemented as an independent embodiment, and steps S2201-S2206 can be implemented as an independent embodiment, but are not limited thereto.

[0484] In some embodiments, steps S2213-S2216 can all be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, and therefore steps S2213-S2216 do not need to be performed.

[0485] In some embodiments, steps S2207-S2216 can all be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, although the second node sends the sixth message to the third node to request the third node to generate the sixth key for the second node, in the case that the third node refuses to generate the sixth key for the second node or the generation of the sixth key fails, the second node cannot determine the first security algorithm and cannot generate the fifth key.

[0486] In some embodiments, other optional implementations described before or after the description corresponding to FIG. 2B can be referred to.

[0487] FIG. 2C is an interaction diagram three of a data security processing method according to an exemplary embodiment. As shown in FIG. 2C, the embodiments of the present disclosure relate to a data security processing method for a communication system 100, and the method includes:

[0488] In step S2301, the terminal generates a first key according to a third key of a third node.

[0489] The communication system can be the communication system shown in FIG. 1A. The terminal is the terminal 101 shown in FIG. 1A. The third node can be one of the network devices 102 shown in FIG. 1A. Exemplarily, the third node can be a core network node.

[0490] In some embodiments, the third node can include, but is not limited to, a security anchor function (SEAF).

[0491] In some embodiments, the third node is a SEAF, and the third key of the third node can be K SEAF .

[0492] In some embodiments, the first key is an intermediate key for generating the second key.

[0493] In some embodiments, the second key is used to protect the communication between the terminal and the second node. Illustratively, the second key is used to protect the NAS communication between the terminal and the second node. Here, the NAS communication security can include the security of the NAS messages.

[0494] In some embodiments, the first key is generated according to the third key and the type of the second node.

[0495] It is noted that the second node can be one of the network devices 102 shown in FIG. 1A. In some embodiments, the second node can be any node in the terminal service network except the third node. Illustratively, the second node can be any core network node in the terminal service network except the third node. It is also illustrative that the second node is not necessarily a core network node.

[0496] The terminal can determine the type of the second node according to the requested network service or function. For example, if the terminal requests a user name session, the type of the second node is SMF. If the terminal requests positioning, the type of the second node can be LMF.

[0497] In some embodiments, the terminal uses a KDF to derive the first key, with the third key as input and the type of the second node as derivation parameter.

[0498] In some other embodiments, the first key is generated according to the third key, a first count value, and the type of the second node; the first count value is used to indicate the number of uplink messages sent by the terminal to the second node.

[0499] Illustratively, the first count value can be the number of uplink NAS messages sent by the terminal to the second node. If the terminal has not sent any uplink NAS message to the second node, the first count value can be 0.

[0500] In some embodiments, the first key is generated according to the third key and the instance ID of the second node.

[0501] In some embodiments, the terminal can be pre-configured with the instance ID of the corresponding second node. In this case, the terminal can also generate the first key according to the instance ID of the second node and the third key.

[0502] In some embodiments, the first key is generated according to the third key, a first count value, and the instance ID of the second node.

[0503] In some embodiments, the terminal ID can also be used as a generation parameter of the first key when the first key is generated.

[0504] In this case, the first key is generated according to the third key and in combination with one or more of the type of the second node, the instance ID of the second node, the first count value, and the terminal ID. If the first key is generated according to the terminal ID and the third key, the first keys corresponding to different terminals are different, thereby realizing isolation of the communication security between different terminals and the second node.

[0505] In some embodiments, the terminal ID can be any information capable of identifying the terminal. Exemplarily, IMSI, IMEI, GUTI, NAI, etc. can be the information of the unique terminal.

[0506] In step S2302, the terminal sends a first message to the first node.

[0507] In some embodiments, the first node can be an access network node, and specifically can be various types of base stations.

[0508] In some embodiments, the first message is not protected by the fourth key.

[0509] It should be noted that, since the second node directly communicating with the terminal is not determined by the third node in the embodiments of the present disclosure, the first message does not need to be forwarded to the second node via the third node. In this case, since the terminal has not established a security context between the terminal and the second node, the terminal cannot protect the first message by the security context between the terminal and the second node.

[0510] The first message at least includes a first count value, which is used to indicate the number of uplink messages sent by the terminal to the second node.

[0511] It should be noted that, since the first message is not protected by the fourth key, the first message can only carry information that does not need to be protected and information necessary for negotiating security algorithms, including the first count value.

[0512] In some embodiments, the first count value is the count of uplink NAS messages sent by the terminal to the second node. Exemplarily, the first count value can be the number of uplink NAS messages that have been sent by the terminal to the second node. If the terminal has not sent any uplink NAS message to the second node, the first count value can be 0.

[0513] In some embodiments, the terminal sends a second RRC message to the first node, and the second RRC message includes the first message that is not protected by the fourth key.

[0514] It should be noted that, in the case where the first message needs to be forwarded to the second node via the first node, the terminal sends a second RRC message carrying the first message to the first node.

[0515] It can be understood that the first message can be carried in the second RRC message by means of a message container.

[0516] In some embodiments, in order to enhance the security of the first message, the second RRC message is protected using an access stratum (AS) security context. Illustratively, the AS security context can include a key for communication between the terminal and the access network node. For example, the second RRC message is encrypted and / or integrity protected.

[0517] In some embodiments, the second RRC message further includes second information, the second information being used to indicate a first capability of the terminal, the first capability being related to security.

[0518] In some embodiments, the second information is used by the second node to determine the first security algorithm.

[0519] It is to be noted that the terminal causes the first node to forward the second information to the second node, so that the second node determines the first security algorithm of the fifth key based on the second information, by carrying the second information in the second RRC message.

[0520] In some embodiments, the second RRC message further includes at least one of: a first indicator, used to indicate a message type of the first message; type information of the second node; an instance ID of the second node; address information of the second node.

[0521] In some embodiments, the type information of the second node is carried in the second RRC message, which can cause the first node to know the type of the second node, and select the second node for the UE according to the location information of the terminal and / or the second node reachable by the first node.

[0522] In some embodiments, the instance ID of the second node can be an identifier of the second node pre-configured on the terminal, etc. In some embodiments, the terminal acquires the instance ID of the second node according to historical communication.

[0523] In some embodiments, the address information of the second node can include, but is not limited to, an Internet Protocol (IP) address.

[0524] Step S2303, the first node sends a fifth message to the second node.

[0525] In some embodiments, the first node sends the fifth message to the second node, the fifth message including the unprotected first message. It can be understood that the first node sends the received unprotected first message to the second node.

[0526] In some embodiments, the first node can only act as a forwarding node of the first message. Illustratively, the first node receives the second RRC message, extracts the first message from the second RRC message, and sends the fifth message including the first message to the second node.

[0527] In some embodiments, the second node is a receiving node of the first message. It can be understood that the first message in the embodiments of the present disclosure is directly sent by the first node to the second node without being sent to the second node through the third node.

[0528] In some embodiments, the fifth message is sent to the second node according to the type information of the second node or the instance ID of the second node in the second RRC message.

[0529] It should be noted that in the case that the first node receives the second RRC message, the first node needs to determine the receiving node of the first message in the second RRC message. If the type information of the second node or the instance ID of the second node is included in the second RRC message, the first node can determine that the second node is the receiving node of the first message according to the type information of the second node or the instance ID of the second node; therefore, the first node sends the fifth message containing the first message to the second node.

[0530] In some embodiments, the fifth message further includes second information. It should be noted that the first node sends the second information to the second node through the fifth message, so that the second node determines the first security algorithm of the fifth key based on the second information.

[0531] Step S2304, the second node sends a sixth message to the third node.

[0532] In some embodiments, the optional implementation of the second node sending the sixth message to the third node can be referred to the related description in the corresponding embodiment S2204 of FIG. 2B.

[0533] Step S2305, the third node generates a sixth key according to the third key of the third node.

[0534] In some embodiments, the third node can be an SEAF, and the third key of the third node can be K SEAF .

[0535] In some embodiments, the sixth key is generated according to the third key and the type information of the second node.

[0536] It can be understood that in the case that the sixth message includes the instance ID of the second node, the third node can generate the sixth key according to the third key and the type information of the second node.

[0537] In some embodiments, the third node uses a key derivation function (KDF) to derive the sixth key with the third key as input and the type information of the second node as derivation parameter.

[0538] In some embodiments, the sixth key is generated according to the third key and the instance ID of the second node.

[0539] It can be understood that, in the case that the sixth message comprises the instance ID of the second node, the third node generates the sixth key according to the third key and the instance ID of the second node.

[0540] In some embodiments, the sixth key is generated according to the third key, the first count value and the instance ID of the second node.

[0541] In some embodiments, the terminal ID can also be used as a generation parameter of the sixth key when the sixth key is generated.

[0542] In this case, the sixth key is generated according to the third key in combination with one or more of the type of the second node, the instance ID of the second node, the first count value and the terminal ID. If the sixth key is generated according to the terminal ID and the third key, the sixth keys corresponding to different terminals are different, thereby realizing isolation of the communication security between different terminals and the second node.

[0543] Step S2306, the third node sends a seventh message to the second node.

[0544] In some embodiments, the seventh message is used to indicate whether the sixth key has been generated.

[0545] In some embodiments, the seventh message can be a key generation response.

[0546] In some embodiments, the seventh message can comprise the sixth key. It should be noted that, after generating the sixth key, the third node can send the seventh message to the second node, so as to send the generated sixth key to the second node through the seventh message, so that the second node generates the fifth key based on the sixth key.

[0547] Step S2307, the second node determines the first security algorithm.

[0548] In some embodiments, the optional implementation manners in which the second node determines the first security algorithm can all refer to the related description in the corresponding embodiment S2107 of FIG. 2A.

[0549] Step S2308, the second node generates the fifth key based on the first security algorithm and the sixth key.

[0550] In some embodiments, the optional implementation manners in which the second node generates the fifth key based on the first security algorithm and the sixth key can all refer to the related description in the corresponding embodiment S2108 of FIG. 2A.

[0551] Step S2309, the second node sends a second message to the first node.

[0552] In some embodiments, the optional implementation that the first node sends the second message to the terminal can be found with reference to the description of corresponding embodiment S2110 in FIG. 2A.

[0553] Step S2310, the first node sends the second message to the terminal.

[0554] In some embodiments, the optional implementation that the first node sends the second message to the terminal can be found with reference to the description of corresponding embodiment S2110 in FIG. 2A.

[0555] Step S2311, the terminal determines the first security algorithm.

[0556] In some embodiments, the optional implementation that the terminal determines the first security algorithm can be found with reference to the description of corresponding embodiment S2111 in FIG. 2A.

[0557] Step S2312, the terminal generates a second key based on the first security algorithm and the first key.

[0558] In some embodiments, the optional implementation that the terminal generates a second key based on the first security algorithm and the first key can be found with reference to the description of corresponding embodiment S2112 in FIG. 2A.

[0559] Step S2313, the terminal sends an indication that the first security algorithm negotiation is completed to the first node.

[0560] In some embodiments, the optional implementation that the terminal sends an indication that the first security algorithm negotiation is completed to the first node can be found with reference to the description of corresponding embodiment S2113 in FIG. 2A.

[0561] Step S2314, the first node sends an indication that the first security algorithm negotiation is completed to the second node.

[0562] In some embodiments, the optional implementation that the first node sends an indication that the first security algorithm negotiation is completed to the second node can be found with reference to the description of corresponding embodiment S2114 in FIG. 2A.

[0563] Step S2315, the second node sends a third message to the first node.

[0564] In some embodiments, the optional implementation that the second node sends a third message to the first node can be found with reference to the description of corresponding embodiment S2115 in FIG. 2A.

[0565] Step S2316, the first node sends the third message to the terminal.

[0566] In some embodiments, the optional implementation of the first node sending the third message to the terminal can refer to the related description in the corresponding embodiment S2116 of FIG. 2A.

[0567] In some embodiments, the term “information” can be replaced by the terms “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “field”, “data”, and the like.

[0568] In some embodiments, “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive” can be replaced by each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, processing by itself, and the like. The protocol may, for example, include at least one of a 3GPP protocol, a Wi-Fi protocol, an audio and / or video protocol.

[0569] In some embodiments, the term “send” can be replaced by the terms “transmit”, “report”, “transmit”, and the like.

[0570] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S2301-S2316. For example, steps S2301-S2312 can be implemented as an independent embodiment, and steps S2301-S2307 can be implemented as an independent embodiment, but are not limited thereto.

[0571] In some embodiments, steps S2313-S2316 can all be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S2313-S2316.

[0572] In some embodiments, steps S2308-S2316 can all be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, although the second node sends the sixth message to the third node to request the third node to generate the sixth key for the second node, in the case that the third node refuses to generate the sixth key for the second node or the generation of the sixth key fails, the second node cannot generate the fifth key.

[0573] In some embodiments, the other optional implementations described before or after the corresponding description of FIG. 2C can be referred to.

[0574] FIG. 3A is a flow diagram illustrating a data security processing method according to an example embodiment. As shown in FIG. 3A, the data security processing method is performed by the terminal 101, and the method comprises the following steps:

[0575] Step S3101, generating a first key.

[0576] In some embodiments, the terminal generates the first key according to a third key of a third node.

[0577] In some embodiments, the related descriptions of the first node, the second node, the third node, the first key, and / or the third key can be found in the corresponding embodiments of FIG. 2A.

[0578] In some embodiments, the optional implementations of the terminal generating the first key according to the third key of the third node can all be found in the related descriptions of S2101 in the corresponding embodiments of FIG. 2A.

[0579] Step S3102, sending a first message.

[0580] In some embodiments, the terminal sends the first message to the first node.

[0581] In some embodiments, the optional implementations of the terminal sending the first message to the first node can all be found in the related descriptions of S2102 in the corresponding embodiments of FIG. 2A.

[0582] Step S3103, receiving a second message.

[0583] In some embodiments, the terminal receives the second message sent by the first node.

[0584] In some embodiments, the optional implementations of the terminal receiving the second message sent by the first node can all be found in the related descriptions of S2110 in the corresponding embodiments of FIG. 2A.

[0585] Step S3104, determining a first security algorithm.

[0586] In some embodiments, the optional implementations of the terminal determining the first security algorithm can all be found in the related descriptions of S2111 in the corresponding embodiments of FIG. 2A.

[0587] Step S3105, generating a second key.

[0588] In some embodiments, the terminal generates the second key based on the first security algorithm and the first key.

[0589] In some embodiments, the related description of the second key can refer to the related description in the corresponding embodiment of FIG. 2A.

[0590] In some embodiments, the optional implementation of the terminal generating the second key based on the first security algorithm and the first key can refer to the related description in the corresponding embodiment S2112 of FIG. 2A.

[0591] In step S3106, the first message is sent.

[0592] In some embodiments, the terminal sends an indication of the completion of the negotiation of the first security algorithm to the first node.

[0593] In some embodiments, the optional implementation of the terminal sending an indication of the completion of the negotiation of the first security algorithm to the first node can refer to the related description in the corresponding embodiment S2113 of FIG. 2A.

[0594] In step S3107, the third message is received.

[0595] In some embodiments, the terminal receives the third message sent by the first node.

[0596] In some embodiments, the optional implementation of the terminal receiving the third message sent by the first node can refer to the related description in the corresponding embodiment S2116 of FIG. 2A.

[0597] The data security processing method according to the embodiments of the present disclosure can include at least one of steps S3101-S3107. For example, steps S3101-S3105 can be implemented as an independent embodiment, and steps S3101-S3102 can be implemented as an independent embodiment, but are not limited thereto.

[0598] In some embodiments, steps S3106-S3107 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S3106-S3107.

[0599] In some embodiments, steps S3103-S3107 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, although the terminal generates the first key and sends the first message, in the case that the third node does not select a suitable second node for the terminal, or the second node selected by the third node for the terminal refuses to communicate with the terminal, the terminal does not need to receive the second message.

[0600] In some embodiments, other optional implementations can be described before or after the corresponding description of FIG. 3A.

[0601] FIG. 3B is a flowchart II illustrating a data security processing method according to an example embodiment. As shown in FIG. 3B, the data security processing method is performed by the terminal 101, and the method comprises the following steps:

[0602] In step S3201, a first key is generated.

[0603] In some embodiments, the terminal generates the first key according to a third key of a third node.

[0604] In some embodiments, the first node, the second node, the third node, the first key, and / or the third key can be described in the corresponding embodiments of FIG. 2B or FIG. 2C.

[0605] In some embodiments, the optional implementation of the terminal generating the first key according to the third key of the third node can be described in the corresponding embodiments of S2201 or S2301 of FIG. 2B or FIG. 2C.

[0606] In step S3202, a first message is sent.

[0607] In some embodiments, the terminal sends the first message to the first node.

[0608] In some embodiments, the terminal sends the first message to the first node without protection by a fourth key.

[0609] In some embodiments, the optional implementation of the terminal sending the first message to the first node can be described in the corresponding embodiments of S2202 or S2302 of FIG. 2B or FIG. 2C.

[0610] In step S3203, a second message is received.

[0611] In some embodiments, the terminal receives the second message sent by the first node.

[0612] In some embodiments, the optional implementation of the terminal receiving the second message sent by the first node can be described in the corresponding embodiments of S2210 or S2310 of FIG. 2B or FIG. 2C.

[0613] In step S3204, a first security algorithm is determined.

[0614] In some embodiments, the optional implementation of the terminal determining the first security algorithm can be described in the corresponding embodiments of S2211 or S2311 of FIG. 2B or FIG. 2C.

[0615] In step S3205, a second key is generated.

[0616] In some embodiments, the terminal generates the second key based on the first security algorithm and the first key.

[0617] In some embodiments, the related description of the second key can refer to the related description in the corresponding embodiments of FIG. 2B or FIG. 2C.

[0618] In some embodiments, the optional implementation of the terminal generating the second key based on the first security algorithm and the first key can refer to the related description in the corresponding embodiments of S2212 of FIG. 2B or S2312 of FIG. 2C.

[0619] Step S3206: sending an indication of completion of the first security algorithm negotiation.

[0620] In some embodiments, the terminal sends the indication of completion of the first security algorithm negotiation to the first node.

[0621] In some embodiments, the optional implementation of the terminal sending the indication of completion of the first security algorithm negotiation to the first node can refer to the related description in the corresponding embodiments of S2213 of FIG. 2B or S2313 of FIG. 2C.

[0622] Step S3207: receiving a third message.

[0623] In some embodiments, the terminal receives the third message sent by the first node.

[0624] In some embodiments, the optional implementation of the terminal receiving the third message sent by the first node can refer to the related description in the corresponding embodiments of S2216 of FIG. 2B or S2316 of FIG. 2C.

[0625] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S3201 to S3207. For example, steps S3201 to S3205 can be implemented as an independent embodiment, and steps S3201 to S3202 can be implemented as an independent embodiment, but are not limited thereto.

[0626] In some embodiments, steps S3206 to S3207 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S3206 to S3207.

[0627] In some embodiments, S3203 to S3207 can all be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, although the second node sends the sixth message to the third node to request the third node to generate the sixth key for the second node, the second node does not need to receive the second message in the case that the third node refuses to generate the sixth key for the second node or the generation of the sixth key fails.

[0628] In some embodiments, other optional implementations can be described before or after the description of the corresponding embodiments of FIG. 3B.

[0629] FIG. 3C is a flow diagram illustrating a data security processing method according to an example embodiment. As shown in FIG. 3C, the embodiments of the present disclosure relate to a data security processing method, which is performed by a terminal 101, and the above method comprises:

[0630] S3301: sending a first message.

[0631] In some embodiments, the terminal sends the first message to the first node.

[0632] In some embodiments, the first message is used to enable the second node to determine the first security algorithm.

[0633] In some embodiments, the optional implementations of the terminal sending the first message to the first node can all be described with reference to the related descriptions in the embodiments of S2102 of FIG. 2A, S2202 of FIG. 2B or S2302 of FIG. 2C.

[0634] S3302: receiving a second message.

[0635] In some embodiments, the terminal receives the second message sent by the first node.

[0636] In some embodiments, the second message is provided by the second node and the second message is used to enable the terminal to determine the first security algorithm.

[0637] In some embodiments, the optional implementations of the terminal receiving the second message sent by the first node can all be described with reference to the related descriptions in the embodiments of S2110 of FIG. 2A, S2210 of FIG. 2B or S2310 of FIG. 2C.

[0638] S3303: generating a second key.

[0639] In some embodiments, the terminal generates the second key based on the first security algorithm and the first key.

[0640] In some embodiments, the second key is used to protect the security of communication between the terminal and the second node.

[0641] In some embodiments, the first key is generated according to a third key of the third node.

[0642] In some embodiments, the terminal generates the second key based on the first security algorithm and the first key, which can be seen in the related description of the corresponding embodiments S2112, S2212 or S2312 in FIG. 2A, FIG. 2B or FIG. 2C.

[0643] FIG. 4A is a flowchart illustrating a data security processing method according to an example embodiment. As shown in FIG. 4A, the embodiments of the present disclosure relate to a data security processing method, which is performed by a second node, and the above method comprises:

[0644] Step S4101, receiving a fourth message.

[0645] In some embodiments, the second node receives the fourth message sent by the third node.

[0646] In some embodiments, the second node receives the fourth message sent by the third node, which can be seen in the related description of the corresponding embodiment S2106 in FIG. 2A.

[0647] Step S4102, determining a first security algorithm.

[0648] In some embodiments, the second node determines the first security algorithm, which can be seen in the related description of the corresponding embodiment S2107 in FIG. 2A.

[0649] Step S4103, generating a fifth key.

[0650] In some embodiments, the second node generates the fifth key based on the first security algorithm and a sixth key.

[0651] In some embodiments, the second node generates the fifth key based on the first security algorithm and the sixth key, which can be seen in the related description of the corresponding embodiment S2108 in FIG. 2A.

[0652] Step S4104, sending a second message.

[0653] In some embodiments, the second node sends the second message to the first node.

[0654] In some embodiments, the second node sends the second message to the first node, which can be seen in the related description of the corresponding embodiment S2109 in FIG. 2A.

[0655] Step S4105, receiving a first message.

[0656] In some embodiments, the second node receives the first message sent by the first node.

[0657] In some embodiments, the second node receives the first message sent by the first node, which can be seen in the corresponding description of the optional implementation of step S2114 in FIG. 2A.

[0658] Step S4106: sending the third message.

[0659] In some embodiments, the second node sends the third message to the first node.

[0660] In some embodiments, the second node sends the third message to the first node, which can be seen in the corresponding description of the optional implementation of step S2115 in FIG. 2A.

[0661] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S4101-S4106. For example, steps S4101-S4104 can be implemented as independent embodiments, but are not limited thereto.

[0662] In some embodiments, steps S4105-S4106 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S4105-S4106.

[0663] In some embodiments, other optional implementations can be seen in the corresponding description of FIG. 4A before or after.

[0664] FIG. 4B is a flow diagram of a data security processing method according to an exemplary embodiment. As shown in FIG. 4B, the embodiments of the present disclosure relate to a data security processing method performed by a second node, and the above method includes:

[0665] Step S4201: receiving the fifth message.

[0666] In some embodiments, the second node receives the fifth message sent by the first node.

[0667] In some embodiments, the second node receives the fifth message sent by the first node, which can be seen in the corresponding description of step S2203 in FIG. 2B or step S2303 in FIG. 2C.

[0668] Step S4202: sending the sixth message.

[0669] In some embodiments, the second node sends the sixth message to the third node.

[0670] In some embodiments, the optional implementation of the second node sending the sixth message to the third node can be found in the corresponding description in embodiment S2204 or S2304 in FIG. 2B or 2C.

[0671] Step S4203, receiving the seventh message.

[0672] In some embodiments, the second node receives the seventh message sent by the third node.

[0673] In some embodiments, the optional implementation of the second node receiving the seventh message sent by the third node can be found in the corresponding description in embodiment S2206 or S2306 in FIG. 2B or 2C.

[0674] Step S4204, determining the first security algorithm.

[0675] In some embodiments, the optional implementation of the second node determining the first security algorithm can be found in the corresponding description in embodiment S2207 or S2307 in FIG. 2B or 2C.

[0676] Step S4205, generating the fifth key.

[0677] In some embodiments, the second node generates the fifth key based on the first security algorithm and the sixth key.

[0678] In some embodiments, the optional implementation of the second node generating the fifth key based on the first security algorithm and the sixth key can be found in the corresponding description in embodiment S2208 or S2308 in FIG. 2B or 2C.

[0679] Step S4206, sending the second message.

[0680] In some embodiments, the second node sends the second message to the first node.

[0681] In some embodiments, the optional implementation of the second node sending the second message to the first node can be found in the corresponding description in embodiment S2209 or S2309 in FIG. 2B or 2C.

[0682] Step S4207, receiving the first message.

[0683] In some embodiments, the second node receives the first message sent by the first node.

[0684] In some embodiments, the optional implementation of the second node receiving the first message sent by the first node can be found in the corresponding description in embodiment S2214 or S2314 in FIG. 2B or 2C.

[0685] Step S4208, sending the third message.

[0686] In some embodiments, the second node sends a third message to the first node.

[0687] In some embodiments, the optional implementation of the second node sending a third message to the first node can refer to the related description in the corresponding embodiment S2215 or S2315 in FIG. 2B or FIG. 2C.

[0688] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S4201-S4208. For example, steps S4201-S4206 can be implemented as independent embodiments, for example, steps S4201-S4203 can be implemented as independent embodiments, but are not limited thereto.

[0689] In some embodiments, steps S4207-S4208 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S4207-S4208.

[0690] In some embodiments, steps S4204-S4208 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, although the second node sends a sixth message to the third node to request the third node to generate a sixth key for the second node, in the case that the third node refuses to generate the sixth key for the second node or the generation of the sixth key fails, the second node cannot determine the first security algorithm and cannot generate the fifth key.

[0691] In some embodiments, other optional implementations can be described before or after the corresponding description of FIG. 4B.

[0692] FIG. 4C is a flow diagram of a data security processing method according to an exemplary embodiment. As shown in FIG. 4C, the embodiments of the present disclosure relate to a data security processing method performed by a second node, and the above method includes:

[0693] Step S4301, receiving a first message.

[0694] In some embodiments, the second node receives the first message sent by the first node or the third node.

[0695] In some embodiments, the first message is used by the second node to determine the first security algorithm.

[0696] In some embodiments, the second node receives the optional implementation of the first message sent by the first node or the third node, which can be seen in the related description in the corresponding embodiment S2106, S2203 or S2303 of FIG. 2A, FIG. 2B or FIG. 2C.

[0697] Step S4302, generating the fifth key.

[0698] In some embodiments, the second node generates the fifth key based on the first security algorithm and the sixth key.

[0699] In some embodiments, the fifth key is used to protect the communication between the second node and the terminal.

[0700] In some embodiments, the sixth key is generated according to the third key of the third node.

[0701] In some embodiments, the optional implementation of the second node generating the fifth key based on the first security algorithm and the sixth key can be seen in the related description in the corresponding embodiment S2108, S2208 or S2308 of FIG. 2A, FIG. 2B or FIG. 2C.

[0702] Step S4303, sending the second message.

[0703] In some embodiments, the second node sends the second message to the first node.

[0704] In some embodiments, the terminal is the receiving node of the second message.

[0705] In some embodiments, the second message is used for the terminal to determine the first security algorithm.

[0706] In some embodiments, the optional implementation of the second node sending the second message to the first node can be seen in the related description in the corresponding embodiment S2109, S2209 or S2309 of FIG. 2A, FIG. 2B or FIG. 2C.

[0707] FIG. 5A is a flow diagram of a data security processing method according to an exemplary embodiment. As shown in FIG. 5A, the data security processing method according to the embodiment of the present disclosure is executed by the third node, and the above method comprises:

[0708] Step S5101, receiving the eighth message.

[0709] In some embodiments, the third node receives the eighth message sent by the first node.

[0710] In some embodiments, the optional implementation of the third node receiving the eighth message sent by the first node can be seen in the related description in the corresponding embodiment S2103 of FIG. 2A.

[0711] Step S5102, determining the second node.

[0712] In some embodiments, the third node determines the optional implementation of the second node, which can be referred to the corresponding description in the embodiment S2104 of FIG. 2A.

[0713] Step S5103, generating the sixth key.

[0714] In some embodiments, the third node generates the sixth key according to the third key of the third node.

[0715] In some embodiments, the third node generates the optional implementation of the sixth key according to the third key of the third node, which can be referred to the corresponding description in the embodiment S2105 of FIG. 2A.

[0716] Step S5104, sending the fourth message.

[0717] In some embodiments, the third node sends the fourth message to the second node.

[0718] In some embodiments, the third node sends the optional implementation of the fourth message to the second node, which can be referred to the corresponding description in the embodiment S2106 of FIG. 2A.

[0719] In some embodiments, the steps S5103 to S5104 can be optional steps. For example, in the case that the third node receives the eighth message, the third node does not select a suitable second node for the terminal, or the second node selected by the third node for the terminal refuses to communicate with the terminal, the steps S5103 to S5104 can not be executed.

[0720] The data security processing method related to the embodiments of the present disclosure can include at least one of the steps S5101 to S5104. For example, the steps S5101 to S5102 can be implemented as an independent embodiment, but are not limited thereto.

[0721] In some embodiments, the steps S5103 to S5104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, in the case that the third node receives the eighth message, the third node does not select a suitable second node for the terminal, or the second node selected by the third node for the terminal refuses to communicate with the terminal, the steps S5103 to S5104 can not be executed.

[0722] In some embodiments, other optional implementations can be referred to the description before or after the corresponding description of FIG. 5A.

[0723] FIG. 8 is a flowchart illustrating a data security processing method according to an example embodiment. As shown in FIG. 8, the data security processing method according to an example embodiment is performed by a third node, and includes the following steps S8001-S8003.

[0724] At step S5201, the sixth message is received.

[0725] In some embodiments, the third node receives the sixth message sent by the second node.

[0726] In some embodiments, the third node receives the sixth message sent by the second node, which can be understood with reference to the optional implementation of step S2204 or S2304 in FIG. 2B or 2C.

[0727] At step S5202, the sixth key is generated.

[0728] In some embodiments, the third node generates the sixth key according to the third key of the third node.

[0729] In some embodiments, the third node generates the sixth key according to the third key of the third node, which can be understood with reference to the optional implementation of step S2205 or S2305 in FIG. 2B or 2C.

[0730] At step S5203, the seventh message is sent.

[0731] In some embodiments, the third node sends the seventh message to the second node.

[0732] In some embodiments, the third node sends the seventh message to the second node, which can be understood with reference to the optional implementation of step S2206 or S2306 in FIG. 2B or 2C.

[0733] In some embodiments, step S5203 can be optional, for example, in the case that the third node receives the sixth message, the third node refuses the sixth key, or the generation of the sixth key fails, step S5203 can not be performed.

[0734] The data security processing method according to an example embodiment can include at least one of steps S5201-S5203. For example, steps S5201-S5202 can be implemented as independent embodiments, but are not limited thereto.

[0735] In some embodiments, step S5203 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, in the case that the third node receives the sixth message, the third node refuses the sixth key, or the generation of the sixth key fails, step S5203 can not be performed.

[0736] In some embodiments, the other optional implementations described before or after the corresponding description of Figure 5B can be referred to.

[0737] Figure 5C is a flow diagram of a data security processing method according to an example embodiment. As shown in Figure 5C, the embodiments of the present disclosure relate to a data security processing method, which is executed by a third node, and the above method comprises:

[0738] Step S5301, generating a sixth key.

[0739] In some embodiments, the third node generates the sixth key according to the third key of the third node.

[0740] In some embodiments, the optional implementations of the third node generating the sixth key according to the third key of the third node can be referred to the related descriptions in the corresponding embodiments S2105, S2205 or S2305 of Figure 2A, Figure 2B or Figure 2C.

[0741] Step S5302, sending the sixth key.

[0742] In some embodiments, the third node sends the sixth key to the second node.

[0743] In some embodiments, the sixth key is used by the second node to generate a fifth key.

[0744] In some embodiments, the fifth key is used to protect the communication security between the second node and the terminal.

[0745] In some embodiments, the optional implementations of the third node sending the sixth key to the second node can be referred to the related descriptions in the corresponding embodiments S2106, S2206 or S2306 of Figure 2A, Figure 2B or Figure 2C.

[0746] Figure 6A is a flow diagram of a data security processing method according to an example embodiment. As shown in Figure 6A, the embodiments of the present disclosure relate to a data security processing method, which is executed by a first node, and the above method comprises:

[0747] Step S6101, receiving a first message.

[0748] In some embodiments, the first node receives the first message sent by the terminal.

[0749] In some embodiments, the optional implementations of the first node receiving the first message sent by the terminal can be referred to the related descriptions in the corresponding embodiment S2102 of Figure 2A.

[0750] Step S6102, sending an eighth message.

[0751] In some embodiments, the first node sends an eighth message to the third node.

[0752] In some embodiments, the optional implementations of the first node sending the eighth message to the third node can be found in the corresponding description in embodiment S2103 in FIG. 2A.

[0753] Step S6103, receiving the second message.

[0754] In some embodiments, the first node receives the second message sent by the second node.

[0755] In some embodiments, the optional implementations of the first node receiving the second message sent by the second node can be found in the corresponding description in embodiment S2109 in FIG. 2A.

[0756] Step S6104, sending the second message.

[0757] In some embodiments, the first node sends the second message to the terminal.

[0758] In some embodiments, the optional implementations of the first node sending the second message to the terminal can be found in the corresponding description in embodiment S2110 in FIG. 2A.

[0759] Step S6105, receiving an indication of completion of the first security algorithm negotiation.

[0760] In some embodiments, the first node receives the indication of completion of the first security algorithm negotiation sent by the terminal.

[0761] In some embodiments, the optional implementations of the first node receiving the indication of completion of the first security algorithm negotiation sent by the terminal can be found in the corresponding description in embodiment S2113 in FIG. 2A.

[0762] Step S6106, sending the first message.

[0763] In some embodiments, the first node sends the indication of completion of the first security algorithm negotiation to the second node.

[0764] In some embodiments, the optional implementations of the first node sending the indication of completion of the first security algorithm negotiation to the second node can be found in the corresponding description in embodiment S2114 in FIG. 2A.

[0765] Step S6107, receiving the third message.

[0766] In some embodiments, the first node receives the third message sent by the second node.

[0767] In some embodiments, the first node receives an optional implementation of the third message sent by the second node, which can be seen in the corresponding embodiment S2115 in FIG. 2A.

[0768] At step S6108, the third message is sent.

[0769] In some embodiments, the first node sends the third message to the terminal.

[0770] In some embodiments, the first node sends an optional implementation of the third message to the terminal, which can be seen in the corresponding embodiment S2116 in FIG. 2A.

[0771] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S6101-S6108. For example, steps S6101-S6104 can be implemented as an independent embodiment, and steps S6101-S6102 can be implemented as an independent embodiment, but are not limited thereto.

[0772] In some embodiments, steps S6105-S6108 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S6105-S6108.

[0773] In some embodiments, steps S6103-S6108 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, although the first node sends the eighth message, in the case that the third node does not select a suitable second node for the terminal, or the second node selected by the third node for the terminal refuses to communicate with the terminal, the first node does not need to receive the second message.

[0774] In some embodiments, other optional implementations can be seen in the description before or after FIG. 6A.

[0775] FIG. 6B is a flow diagram of a data security processing method according to an exemplary embodiment. As shown in FIG. 6B, the embodiments of the present disclosure relate to a data security processing method performed by a first node, and the above method includes:

[0776] At step S6201, the first message is received.

[0777] In some embodiments, the first node receives the first message sent by the terminal.

[0778] In some embodiments, the first node receives the indication of the first security algorithm negotiation completion sent by the terminal, which can be seen in the corresponding description in S2213 or S2313 in FIG. 2B or FIG. 2C.

[0779] Step S6202, sending the fifth message.

[0780] In some embodiments, the first node sends the fifth message to the second node.

[0781] In some embodiments, the first node sends the fifth message to the second node, which can be seen in the corresponding description in S2203 or S2303 in FIG. 2B or FIG. 2C.

[0782] Step S6203, receiving the second message.

[0783] In some embodiments, the first node receives the second message sent by the second node.

[0784] In some embodiments, the first node receives the second message sent by the second node, which can be seen in the corresponding description in S2209 or S2309 in FIG. 2B or FIG. 2C.

[0785] Step S6204, sending the second message.

[0786] In some embodiments, the second node sends the second message to the terminal.

[0787] In some embodiments, the second node sends the second message to the terminal, which can be seen in the corresponding description in S2210 or S2310 in FIG. 2B or FIG. 2C.

[0788] Step S6205, receiving the indication of the first security algorithm negotiation completion.

[0789] In some embodiments, the first node receives the indication of the first security algorithm negotiation completion sent by the terminal.

[0790] In some embodiments, the first node receives the indication of the first security algorithm negotiation completion sent by the terminal, which can be seen in the corresponding description in S2213 or S2313 in FIG. 2B or FIG. 2C.

[0791] Step S6206, sending the first message.

[0792] In some embodiments, the first node sends the indication of the first security algorithm negotiation completion to the second node.

[0793] In some embodiments, the optional implementation of the first node sending the indication of the completion of the first security algorithm negotiation to the second node can be found in the corresponding description of S2214 or S2314 in FIG. 2B or FIG. 2C.

[0794] Step S6207, receiving the third message.

[0795] In some embodiments, the first node receives the third message sent by the second node.

[0796] In some embodiments, the optional implementation of the first node receiving the third message sent by the second node can be found in the corresponding description of S2215 or S2315 in FIG. 2B or FIG. 2C.

[0797] Step S6208, sending the third message.

[0798] In some embodiments, the first node sends the third message to the terminal.

[0799] In some embodiments, the optional implementation of the first node sending the third message to the terminal can be found in the corresponding description of S2216 or S2316 in FIG. 2B or FIG. 2C.

[0800] The data security processing method related to the embodiments of the present disclosure can include at least one of steps S6201-S6208. For example, steps S6201-S6204 can be implemented as an independent embodiment, and steps S6201-S6202 can be implemented as an independent embodiment, but are not limited thereto.

[0801] In some embodiments, steps S6205-S6208 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, after the terminal generates the second key, there is no need to communicate with the second node, so there is no need to perform steps S6205-S6208.

[0802] In some embodiments, steps S6203-S6208 can be optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, although the first node sends the fifth message, in the case that the third node refuses to generate the sixth key for the second node or the generation of the sixth key fails, the first node does not need to receive the second message.

[0803] In some embodiments, other optional implementations can be found in the description before or after FIG. 6B.

[0804] FIG. 6C is a flowchart illustrating a twelfth method of data security processing, according to an example embodiment. As shown in FIG. 6C, the present embodiment relates to a method of data security processing, performed by a first node, the method comprising:

[0805] At step S6301, the first message is received.

[0806] In some embodiments, the first node receives the first message sent by the terminal.

[0807] In some embodiments, the optional implementations of the first node receiving the first message sent by the terminal can be found in the corresponding embodiments S2102, S2202 or S2302 of FIG. 2A, FIG. 2B or FIG. 2C.

[0808] At step S6302, the first message is sent.

[0809] In some embodiments, the first node sends the first message to the second node or the third node.

[0810] In some embodiments, the first message is used to cause the second node to determine the first security algorithm.

[0811] In some embodiments, the optional implementations of the first node receiving the first message sent by the terminal can be found in the corresponding embodiments S2103, S2203 or S2303 of FIG. 2A, FIG. 2B or FIG. 2C.

[0812] At step S6303, the second message is received.

[0813] In some embodiments, the first node receives the second message sent by the second node.

[0814] In some embodiments, the optional implementations of the first node receiving the second message sent by the second node can be found in the corresponding embodiments S2109, S2209 or S2309 of FIG. 2A, FIG. 2B or FIG. 2C.

[0815] At step S6304, the second message is sent.

[0816] In some embodiments, the first node sends the second message to the terminal.

[0817] In some embodiments, the second message is used to cause the terminal to determine the first security algorithm.

[0818] In some embodiments, the first security algorithm is used to generate a second key by the terminal.

[0819] In some embodiments, the second key is used to protect the communication security between the terminal and the second node.

[0820] In some embodiments, the first node sends the second message to the terminal, which can be seen in the optional implementation of the second message sent by the first node to the terminal in the corresponding embodiments S2110, S2210 or S2310 of FIG. 2A, FIG. 2B or FIG. 2C.

[0821] FIG. 7 is an interaction diagram four of a data security processing method according to an exemplary embodiment. As shown in FIG. 7, the embodiments of the present disclosure relate to a data security processing method, which is used in the communication system 100, and the method comprises one of the following steps:

[0822] In step S7101, the terminal sends a first message to the first node.

[0823] In step S7102, the first node sends the first message to the second node or the third node.

[0824] In some embodiments, the first message is used by the second node to determine the first security algorithm.

[0825] In step S7103, the third node generates a sixth key according to the third key of the third node.

[0826] In step S7104, the third node sends the sixth key to the second node.

[0827] In step S7105, the second node generates a fifth key based on the first security algorithm and the sixth key.

[0828] In some embodiments, the fifth key is used to protect the communication security between the second node and the terminal.

[0829] In step S7106, the second node sends a second message to the first node.

[0830] In step S7107, the first node sends the second message to the terminal.

[0831] In some embodiments, the second message is used by the terminal to determine the first security algorithm.

[0832] In step S7108, the terminal generates a second key based on the first security algorithm and the first key.

[0833] In some embodiments, the second key is used to protect the communication security between the terminal and the second node; and the first key is generated according to the third key of the third node.

[0834] In some embodiments, the above method can include the methods of the above-mentioned communication system side, terminal side, first node side, second node side, third node side, etc. embodiments, which are not described here.

[0835] In order to better understand the embodiments of the present disclosure, the present disclosure is further illustrated by some exemplary embodiments. In order to better understand the embodiments of the present disclosure, the present disclosure is further illustrated by some exemplary embodiments.

[0836] In some embodiments, the current 5G security key hierarchy does not support protecting NAS signaling between the UE and NFs other than the AMF. And the NAS security mode command (SMC) for NAS security algorithm (terminal and AMF) negotiation only supports performing between the terminal and the AMF, and other NFs do not support the NAS SMC message.

[0837] In some embodiments, NAS security establishment can be enabled by security mode negotiation (e.g., security algorithm) between the terminal and the NF to support protection for the 6G multi-NAS network architecture.

[0838] In some embodiments, in the 5G system, the key for NAS signaling is derived by the terminal and the AMF based on the key hierarchy. As shown in FIG. 8A, FIG. 8A is a schematic diagram of a key hierarchy I according to an exemplary embodiment.

[0839] The key of the AMF in the serving network (i.e., K AMF ) is the key derived by the terminal and the SEAF from K SEAF . When performing horizontal key derivation, K AMF is further derived by the terminal and the source AMF.

[0840] The key for NAS signaling can include: K NASint and K NASenc ; wherein K NASint is the key derived by the terminal and the AMF from K AMF for integrity protection of NAS signaling based on a specific integrity algorithm. K NASenc is the key derived by the terminal and the AMF from K AMF for confidentiality protection of NAS signaling based on a specific encryption algorithm.

[0841] In some embodiments, in order to protect the NAS / NF signaling between the terminal and the core NF other than the AMF, K NF can be used as the security root for NAS / NF signaling between the terminal and the NF. In the 6G system, assuming that the AMF determines and selects the NF (e.g., LMF, SMF, etc.) that can directly communicate with the terminal in the initial NAS procedure with the target NF, the terminal and the AMF derive K AMF from K NF respectively. As shown in FIG. 8B and FIG. 8C, FIG. 8B is a schematic diagram of a key hierarchy II according to an exemplary embodiment; and FIG. 8C is a schematic diagram of a key hierarchy III according to an exemplary embodiment.

[0842] Based on K NF, the terminal and the target NF further derive a security key for NAS / NF signaling, i.e., K NFint for integrity protection of NAS / NF signaling between the terminal and the NF NASenc .

[0843] In some embodiments, when the terminal and the NF derive K NF for NAS / NF signaling based on K NFint and K NASenc , the following parameters shall be used to form the input parameters of the Key Derivation Function (KDF).

[0844] FC = To Be Determined (TBD);

[0845] P0 = Algorithm type distinguisher, e.g., the values of the algorithm type distinguisher are different for integrity algorithms or encryption algorithms;

[0846] L0 = Length of the algorithm type distinguisher;

[0847] P1 = Algorithm identity, typical algorithm identities can include but are not limited to the ID of AES, the ID of ZUC, etc.

[0848] L1 = Length of the algorithm identity;

[0849] The input key can be 256-bit K NF .

[0850] Since the algorithm identity is an input parameter, the terminal and the NF need to agree on the algorithm applied to the security context of NAS / NF. Since the terminal and the NF can have different algorithm capabilities, and / or the terminal and the NF can have different network configurations on algorithm priority. The terminal needs to negotiate the security algorithm with the target NF when establishing the NAS / NF security context with the target NF.

[0851] In some embodiments, in a 6G system, it can be assumed that a RAN node is unable to determine or select NFs (e.g. LMF or SMF, etc.) that can directly communicate with a terminal, and all NFs capable of communicating with a terminal and a RAN node are selected or determined by an AMF in an initial NAS procedure. For example, when a terminal sends an initial NAS / LPP message to an LMF, the RAN node first sends the NAS / LPP message to the AMF, and the AMF selects an LMF for the UE. In this way, it can be ensured that any initial NAS / NF message sent by the terminal to a target NF other than the AMF is sent after the terminal establishes NAS security with the AMF. Since the initial NAS / NF message for the NF needs to be sent to the AMF through the RAN node, the terminal can use the existing NAS / AMF security context between the terminal and the AMF to protect the initial NAS / NF message for the NF.

[0852] FIG. 8D is a schematic diagram illustrating an interaction of NAS security establishment by an AMF generating a key, according to an example embodiment.

[0853] 1. Before the terminal initiates a NAS message (e.g. NAS / LPP message) to an LMF through a RAN node, the terminal derives K AMF from K NF , e.g. K LMF for LMF, with its own ID, type or instance ID of the target NF, and uplink NAS / LMF COUNT. Note that K AMF was previously derived by the UE and used for initial NAS message with the AMF.

[0854] 2. In the case that the terminal does not have a NAS / LMF security context, the initial NAS / LPP message is protected using the existing NAS / AMF security context; and the protected NAS / LPP message is encapsulated in a RRC message.

[0855] It is noted that the terminal can include an indicator of the initial NAS / LPP message or an indicator of AMF forwarding in the RRC message. The terminal can also include the type or instance identification ID of the target NF (i.e. LMF) in the RRC message. The RRC message is protected using existing AS security.

[0856] 3. The RAN node forwards the NAS / LPP message protected by the NAS / AMF security context to the AMF based on the received indicator of the initial NAS / LPP message or indicator of AMF forwarding. The RAN node can carry the type of the target NF in the message sent to the AMF.

[0857] 4. When the AMF receives the NAS / LPP message protected by NAS / AMF security context, the AMF decodes and verifies the message, and then selects the target NF (i.e. LMF) according to the type of the received NAS / LPP message or the type of the target NF indicated by the RAN node. After selecting the LMF, the AMF derives the K AMF from the terminal ID, the type or identity of the target NF, and the NAS / LPP COUNT of the received NAS / LPP message. LMF .

[0858] 5. The AMF sends the message to the selected LMF; the sent message includes the decoded NAS / LPP message, the derived K LMF , the determined security capability of the terminal from the terminal security context, and the information of the RAN node (e.g. RAN node ID or address).

[0859] 6. The LMF selects the integrity algorithm and the encryption algorithm applied to the NAS / LMF security protection based on its capability of supporting security algorithms and the received security capability of the terminal. Based on the selected integrity algorithm, the encryption algorithm, and the received K LMF , the LMF derives the NAS / LMF keys (i.e. the key K LMF for integrity protection of NAS / LMF signaling and the key K LMFint for confidentiality protection of NAS / LMF signaling) from the K LMFenc . At this time, the LMF establishes the security context for NAS / LMF.

[0860] 7. Before sending the NAS / LMF SMC message, the LMF activates the integrity protection for NAS / LMF signaling using the K LMFint .

[0861] 8. The LMF sends the NAS / LMF SMC message to the terminal.

[0862] Here, the NAS / LMF SMC message includes at least the security capability of the terminal and the selected security algorithms (i.e. the integrity algorithm and the encryption algorithm). The NAS / LMF SMC message is integrity protected using the K LMFint . The NAS / LMF SMC message can be sent by the LMF directly to the RAN node; or, can be sent to the RAN node through the AMF.

[0863] Here, if the message sent in step 5 includes the information of the RAN node, the LMF can directly send the NAS / LMF SMC message to the RAN node.

[0864] 9. The RAN node encapsulates the integrity-protected NAS / LMF SMC message within an RRC message and sends it to the terminal. The RAN node can store the selected LMF information in the terminal's security context.

[0865] 10. The terminal, based on the security algorithm in the received NAS / LMF SMC message, selects from K... LMF Derive the key for NAS / LMF signaling (i.e., the key K used for integrity protection of NAS / LMF signaling). LMFint and the key K used for confidentiality protection of NAS / LMF signaling LMFenc At this point, the terminal establishes the NAS / LMF security context. From this step onwards, the shared NAS / LMF security context between the terminal and the LMF has been established.

[0866] 11. The terminal uses the NAS / LMF security context to verify the integrity protection of the NAS / LMF SMC message.

[0867] 12. The terminal uses the NAS / LMF security context to protect the NAS / LMF SMC completion message and carries the NAS / LMF SMC completion message in the RRC message. Here, the NAS / LMF SMC completion message includes the complete initial NAS / LPP message.

[0868] 13. The RAN node sends the protected NAS / LMF SMC completion message to the LMF.

[0869] It should be noted that since the RAN node has already stored the LMF information in the terminal's context in step 9, the RAN node can directly send the protected NAS / LMF SMC completion message to the LMF.

[0870] In some embodiments, the LMF decodes and verifies the received NAS / LMF SMC completion message based on the NAS / LMF security context.

[0871] 14. The LMF sends a response message to the initial NAS / LMF message.

[0872] Here, the response message is protected by the NAS / LMF security context.

[0873] 15. The RAN node encapsulates the protected response message in an RRC message and sends it to the UE.

[0874] In some embodiments, it is assumed that in a 6G system, all NFs capable of communicating with terminals and RAN nodes are not selected or determined by the AMF. Then, the terminal and SEAF can obtain information from K. SEAF Derivation of KNF Based on K NF , the terminal and the target NF further derive the security key for NAS / NF signaling, i.e., K NFint for integrity protection of NAS / NF signaling between the terminal and the NF, and K NASenc for confidentiality protection of NAS / NF signaling between the terminal and the NF. As shown in FIG. 8E, which is a diagram illustrating a key hierarchy four, according to an example embodiment.

[0875] In some embodiments, the NF can send a key generation request to the SEAF or the AMF upon receiving the initial NAS / NF message sent by the terminal through the RAN node.

[0876] It can be understood that the NF sends a key generation request to the SEAF to derive K SEAF from K NF through the SEAF. Alternatively, the NF sends a key generation request to the AMF to derive K AMF from K NF through the AMF.

[0877] As shown in FIG. 8F, which is a diagram illustrating the interaction of NAS security establishment through the SEAF or the AMF, according to an example embodiment.

[0878] 1. Before the terminal initiates a NAS message (e.g., NAS / LPP message) to the LMF through the RAN node, the terminal derives K SEAF from K AMF or K NF . For example, K LMF for the LMF is K NF with its own ID, the type or instance ID of the target NF, and the uplink NAS / LMF COUNT.

[0879] 2. The terminal encapsulates the unprotected NAS / LPP message in a RRC message.

[0880] In some embodiments, if K NF is derived based on K SEAF , the RRC message can further include the security capability of the terminal.

[0881] In some embodiments, the terminal can also include the type or instance ID of the target NF (i.e., LMF) in the RRC message. The RRC message is protected using existing AS security.

[0882] NOTE: The NAS / LMF security context cannot be determined at this step in case the terminal does not determine a mutually agreed security algorithm. Therefore, the terminal cannot protect the initial NAS / LPP message at this step. The initial NAS / LPP message shall only include the minimum required information, i.e. subscription identifier (e.g. SUCI or GUTI), security capabilities of the terminal, etc.

[0883] 3. The RAN forwards the unprotected NAS / LPP message and the security capabilities of the terminal to the LMF based on the type of the initial NAS / LPP message received or the type of the target NF indicated by the terminal.

[0884] 4. Upon reception of the unprotected NAS / LPP message, the LMF sends a key generation request to the SEAF or AMF. The key generation request can include the terminal ID (e.g. IMSI, SUPI, etc.) and the NAS / LMF COUNT.

[0885] NOTE: The LMF can obtain the terminal identity from the terminal through the NAS / LPP message or from the RAN node through IP mapping. The LMF can obtain the NAS / LMF COUNT through the NAS / LPP message.

[0886] 5. The SEAF or AMF derives K SEAF or K AMF from the received terminal identity and NAS / LMF COUNT and the type or instance ID of the requesting NF (i.e. LMF). LMF .

[0887] 6. The SEAF returns a key generation response to the LMF including K LMF . Alternatively, the AMF returns a key generation response to the LMF including K LMF and the security capabilities of the terminal determined based on the terminal's security context.

[0888] Steps 7 to 15 are the same as steps 6 to 15 in Figure 8D. But in step 12 in the present embodiment, the NAS SMC complete message includes the complete initial NAS / LMF message; because the unprotected initial NAS / LMF message sent in step 2 only contains the minimum information.

[0889] In some embodiments, the operations that the terminal can perform include, but are not limited to, at least one of the following:

[0890] The terminal protects the initial NAS / NF message using the NAS / AMF security context;

[0891] The terminal sends the terminal security capabilities together with the initial NAS / NF message to the target NF;

[0892] the terminal indicates an initial NAS / NF message or indicates the AMF to forward;

[0893] the terminal receives an integrity protected NAS / NF SMC message sent from the target NF;

[0894] the terminal derives a NAS / NF security context from a security algorithm included in the NAS / NF SMC message received from the target NF;

[0895] the terminal protects a NAS / NF SMC complete message using the NAS / NF security context and sends the protected NAS / NF SMC complete message to the target NF.

[0896] In some embodiments, the operations that the RAN node can perform include, but are not limited to, at least one of the following:

[0897] if the UE indicates an initial NAS / NF message or indicates the AMF to forward, the RAN node forwards a NAS / NF message protected by a NAS / AMF security context to the AMF;

[0898] if the UE indicates at least a type of the target NF or an instance ID, the RAN node sends an unprotected NAS / NF message received from the terminal to the target NF without going through the AMF;

[0899] the RAN node receives a NAS / NF SMC message directly from the target NF or the RAN node receives the NAS / NF SMC message from the target NF through the AMF;

[0900] the RAN node forwards the received NAS / NF SMC message to the terminal;

[0901] the RAN node receives a NAS / NF SMC complete message from the terminal;

[0902] the RAN node forwards the received NAS / NF SMC complete message to the target NF.

[0903] In some embodiments, the operations that the AMF can perform include, but are not limited to, at least one of the following:

[0904] the AMF sends the terminal security capability retrieved from the terminal context together with the decoded NAS / NF message to the target NF;

[0905] the AMF receives a NAS / NF SMC message from the target NF;

[0906] the AMF forwards the received NAS / NF SMC message to the RAN node;

[0907] The AMF sends the terminal security capabilities and the derived K NF together to the target NF.

[0908] In some embodiments, the operations that the NF can perform include, but are not limited to, at least one of the following:

[0909] The NF receives the decoded initial NAS / NF message from the AMF;

[0910] The NF receives the terminal security capabilities from the AMF;

[0911] The NF selects the NAS / NF security algorithm according to its own security capabilities and the received terminal security capabilities;

[0912] The NF generates the NAS / NF SMC message and integrity protects the NAS / NF SMC message; the NAS / NF SMC message includes the selected NAS / NF algorithm;

[0913] The NF sends the integrity protected NAS / NF SMC message to the terminal through the AMF and / or the RAN node;

[0914] The NF receives the protected NAS / NF SMC complete message sent by the terminal through the RAN node;

[0915] The NF responds to the complete initial NAS / NF message sent by the terminal through the RAN node;

[0916] The NF sends a key generation request to the AMF;

[0917] The NF receives a key generation response sent by the AMF, the key generation response including the terminal security capabilities and the derived K NF .

[0918] Embodiments of the present disclosure also provide a device for implementing any of the above methods, for example, a device is provided, which includes units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another device is provided, which includes units or modules for implementing the steps performed by the network device (for example, an access network device, or a core network device, etc.) in any of the above methods.

[0919] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the above units or modules are realized by the design of the logical relationship of elements in the circuit; for example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.

[0920] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuits, and the logical relationship of the hardware circuits is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0921] FIG. 9A is a structural schematic diagram of a terminal according to an exemplary embodiment. As shown in FIG. 9A, FIG. 9A is a structural schematic diagram of a first information indication apparatus according to an exemplary embodiment. The present embodiment provides a terminal, comprising:

[0922] The sending module 9101 is configured to send a first message to a first node, the first message being used for the second node to determine a first security algorithm;

[0923] The receiving module 9102 is configured to receive a second message sent by the first node; the second message is provided by the second node and is used for the terminal to determine the first security algorithm;

[0924] The processing module 9103 is configured to generate a second key based on the first security algorithm and a first key; the second key is used to protect the communication security between the terminal and the second node; and the first key is generated according to a third key of a third node.

[0925] Exemplarily, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the terminal.

[0926] In some embodiments, the processing module can be configured to perform, by the terminal, steps related to information processing in any one of the data security processing methods.

[0927] In some embodiments, the sending module can be configured to perform, by the terminal, steps related to information sending in any one of the data security processing methods.

[0928] In some embodiments, the receiving module can be configured to perform, by the terminal, steps related to information receiving in any one of the data security processing methods.

[0929] In some embodiments, the sending module is configured to perform one of the following:

[0930] sending, to the first node, a first radio resource control (RRC) message; the first RRC message comprises a first message protected by a fourth key; the fourth key is used to protect communication security between the terminal and a third node;

[0931] sending, to the first node, a second RRC message; the second RRC message comprises the first message unprotected by the fourth key.

[0932] In some embodiments, the first RRC message comprises at least one of the following: a first indicator indicating a message type of the first message; a second indicator indicating that the first node forwards the first message to the third node; type information of the second node; an instance ID of the second node.

[0933] In some embodiments, the second RRC message comprises at least one of the following: the first indicator indicating the message type of the first message; the type information of the second node; the instance ID of the second node.

[0934] In some embodiments, the first RRC message is protected by an access stratum (AS) security context of the terminal.

[0935] In some embodiments, the second RRC message is protected by the AS security context of the terminal.

[0936] In some embodiments, the receiving module is configured to receive, from the first node, a third RRC message, the third RRC message comprising a second message, the second message being integrity protected by a fifth key; the fifth key being generated according to a sixth key and a first security algorithm.

[0937] In some embodiments, the second message comprises at least one of the following: algorithm identification information identifying the first security algorithm; second information indicating a first capability of the terminal, the first capability being related to security.

[0938] In some embodiments, the processing module is configured to perform one of the following:

[0939] generating the second key based on the first key, the algorithm identification information, and the algorithm type information;

[0940] generating the second key based on the first key, the algorithm identification information, a length of the algorithm identification information, the algorithm type information, and a length of the algorithm type information.

[0941] In some embodiments, the sending module is configured to send, to the first node, a fourth RRC message, the fourth RRC message including an indication of completion of the first security algorithm negotiation.

[0942] In some embodiments, the receiving module is configured to receive a fifth RRC message sent by the first node, the fifth RRC message including a third message, the third message being a response message of the first message.

[0943] In some embodiments, the first message includes at least one of the following: NAS signaling; an identification ID of the terminal; and a first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node.

[0944] In some embodiments, the processing module is configured to perform one of the following:

[0945] generating the first key according to the third key, the first count value, and type information of the second node;

[0946] generating the first key according to the third key, the first count value, and an instance ID of the second node.

[0947] FIG. 9B is a schematic diagram of a structure of a second node according to an exemplary embodiment. As shown in FIG. 9B, the present disclosure provides a second node, which includes:

[0948] The receiving module 9201 is configured to receive a first message sent by the first node or the third node, the first message being used by the second node to determine the first security algorithm;

[0949] The processing module 9202 is configured to generate a fifth key based on the first security algorithm and a sixth key, the fifth key being used to protect the communication security between the second node and the terminal, and the sixth key being generated according to a third key of the third node;

[0950] The sending module 9203 is configured to send, to the terminal through the first node, a second message, the second message being used by the terminal to determine the first security algorithm.

[0951] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the second node.

[0952] In some embodiments, the processing module can be configured to perform, by the second node, steps related to information processing in any one of the data security processing methods.

[0953] In some embodiments, the sending module can be configured to perform, by the second node, steps related to information sending in any one of the data security processing methods.

[0954] In some embodiments, the receiving module can be configured to perform, by the second node, steps related to information receiving in any one of the data security processing methods.

[0955] In some embodiments, the receiving module is configured to receive a fourth message sent by the third node, the fourth message comprising at least one of: the first message decoded based on the fourth key; the sixth key; second information indicating a first capability of the terminal, the first capability being related to security; identification information of the first node; address information of the first node.

[0956] In some embodiments, the receiving module is configured to receive a fifth message sent by the first node, the fifth message comprising at least one of: the first message unprotected by the fourth key; second information indicating a first capability of the terminal, the first capability being related to security.

[0957] In some embodiments, the sending module is configured to send, to the third node, a sixth message for requesting the third node to generate the sixth key for the second node.

[0958] The receiving module is configured to receive a seventh message sent by the third node, the seventh message comprising the sixth key.

[0959] In some embodiments, the processing module is configured to determine fourth information according to the second information and third information, the third information indicating a first capability of the second node, and the fourth information indicating a first security algorithm selected by the second node.

[0960] In some embodiments, the fourth information comprises algorithm identification information for identifying the first security algorithm.

[0961] In some embodiments, the processing module is configured to perform one of:

[0962] generate a fifth key based on the sixth key, the algorithm identification information, and the algorithm type information;

[0963] generate a fifth key based on the sixth key, the algorithm identification information, a length of the algorithm identification information, the algorithm type information, and a length of the algorithm type information.

[0964] In some embodiments, the processing module is configured to perform integrity protection on the second message using a fifth key, the second message comprising at least one of: the fourth information; the second information;

[0965] The sending module is configured to send, by the first node, the second message to the terminal.

[0966] In some embodiments, the receiving module is configured to receive an indication of completion of the first security algorithm negotiation sent by the first node, the indication of completion of the first security algorithm negotiation being protected by a second key; the second key being used to protect the communication security between the terminal and the second node.

[0967] The sending module is configured to send, by the first node, a third message to the terminal, the third message being a response message of the first message, the third message being protected by a fifth key.

[0968] FIG. 9C is a structural schematic diagram of a third node according to an exemplary embodiment. As shown in FIG. 9C, the embodiments of the present disclosure provide a third node, which comprises:

[0969] The processing module 9301 is configured to generate a sixth key according to a third key of the third node;

[0970] The sending module 9302 is configured to send the sixth key to the second node, the sixth key being used by the second node to generate a fifth key, the fifth key being used to protect the communication security between the second node and the terminal.

[0971] In some embodiments, the third node can further comprise a receiving module.

[0972] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the third node.

[0973] In some embodiments, the processing module can be used by the third node to perform the information processing related steps in any one of the data security processing methods.

[0974] In some embodiments, the sending module can be used by the third node to perform the information sending related steps in any one of the data security processing methods.

[0975] In some embodiments, the receiving module can be used by the third node to perform the information receiving related steps in any one of the data security processing methods.

[0976] In some embodiments, the receiving module is configured to receive an eighth message sent by the first node; the eighth message comprising the first message, the first message being protected by a fourth key; the fourth key being used to protect the communication security between the terminal and the third node.

[0977] The processing module is configured to decode the first message by using the fourth key; and generate the sixth key based on the third key and the decoded first message.

[0978] In some embodiments, the first message comprises at least one of the following: NAS signaling; an identity ID of the terminal; and a first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node.

[0979] In some embodiments, the eighth message further comprises at least one of the following: type information of the second node; and an instance ID of the second node.

[0980] In some embodiments, the processing module is configured to perform at least one of the following:

[0981] determine the second node according to the type information of the second node;

[0982] determine the second node according to the instance ID of the second node;

[0983] determine the second node according to the message type of the first message;

[0984] determine the second node according to the information content of the first message.

[0985] In some embodiments, the sending module is configured to send, to the second node, a fourth message, the fourth message comprising at least one of the following: the first message decoded based on the fourth key; the sixth key; second information used to indicate a first capability of the terminal, the first capability being related to security; identification information of the first node; and address information of the first node.

[0986] In some embodiments, the receiving module is configured to receive a sixth message sent by the second node, the sixth message being used to request the third node to generate the sixth key for the second node;

[0987] The processing module is configured to generate the sixth key based on the third key and the sixth message.

[0988] In some embodiments, the sixth message comprises at least one of the following: the terminal ID; and the first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node.

[0989] In some embodiments, the sending module is configured to send, to the second node, a seventh message, the seventh message comprising the sixth key.

[0990] In some embodiments, the processing module is configured to perform at least one of the following:

[0991] generate the sixth key according to the third key, the type of the second node, and the first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node;

[0992] generate a sixth key according to the third key, an instance identifier ID of the second node, and a first count value.

[0993] FIG. 9D is a schematic diagram of a structure of a first node according to an example embodiment. As shown in FIG. 9D, the embodiments of the present disclosure provide a first node, which includes:

[0994] The receiving module 9401 is configured to receive the first message sent by the terminal.

[0995] The sending module 9402 is configured to send the first message to the second node or the third node, and the first message is used for the second node to determine the first security algorithm.

[0996] The receiving module 9401 is further configured to receive the second message sent by the second node.

[0997] The sending module 9402 is further configured to send the second message to the terminal, and the second message is used for the terminal to determine the first security algorithm; and the first security algorithm is used for the terminal to generate a second key, and the second key is used for protecting the communication security between the terminal and the second node.

[0998] In some embodiments, the third node can further include a processing module.

[0999] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first node.

[1000] In some embodiments, the processing module can be used for the first node to perform the information processing related steps in any one of the data security processing methods.

[1001] In some embodiments, the sending module can be used for the first node to perform the information sending related steps in any one of the data security processing methods.

[1002] In some embodiments, the receiving module can be used for the first node to perform the information receiving related steps in any one of the data security processing methods.

[1003] In some embodiments, the receiving module is configured to perform at least one of the following:

[1004] receive a first RRC message sent by the terminal, and the first RRC message includes the first message protected by a fourth key, and the fourth key is used for protecting the communication security between the terminal and the third node;

[1005] receive a second RRC message sent by the terminal, and the second RRC message includes the first message not protected by the fourth key.

[1006] In some embodiments, the first RRC message comprises at least one of: a first indicator indicating a message type of the first message; a second indicator indicating that the first node forwards the first message to the third node; type information of the second node; and an instance ID of the second node.

[1007] In some embodiments, the sending module is configured to send, to the third node, an eighth message according to the first indicator or the second indicator in the first RRC message, the eighth message comprising the first message.

[1008] In some embodiments, the second RRC message comprises at least one of: a first indicator indicating a message type of the first message; type information of the second node; and an instance ID of the second node.

[1009] In some embodiments, the sending module is configured to send, to the second node, a fifth message according to the type information of the second node or the instance ID of the second node in the second RRC message, the fifth message comprising at least one of: the first message unprotected by the fourth key; and second information indicating a first capability of the terminal, the first capability being related to security.

[1010] In some embodiments, the sending module is configured to send, to the terminal, a third RRC message, the third RRC message comprising a second message, the second message being integrity protected by a fifth key, the fifth key being generated according to the sixth key and a first security algorithm, the fifth key being used to protect communication between the second node and the terminal.

[1011] In some embodiments, the receiving module is configured to receive a fourth RRC message sent by the terminal, the fourth RRC message comprising an indication of completion of negotiation of the first security algorithm.

[1012] The sending module is configured to send, to the second node, an indication of completion of negotiation of the first security algorithm.

[1013] In some embodiments, the receiving module is configured to receive a third message sent by the second node, the third message being protected by the fifth key, the third message being a response message of the first message.

[1014] The sending module is configured to send, to the terminal, a fifth RRC message, the fifth RRC message comprising the third message.

[1015] FIG. 10A is a structural schematic diagram of a communication device according to an exemplary embodiment. The communication device 1100 can be a network device (e.g., an access network device or a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above data security processing methods. The communication device 1100 can be used to implement the data security processing method described in the above method embodiments, and specific implementation can be referred to the description in the above method embodiments.

[1016] As shown in FIG. 10A, the communication device 1100 includes one or more processors 1101. The processor 1101 can be a general purpose processor or a special purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. The processor 1101 is used to invoke instructions to enable the communication device 1100 to perform any of the above communication methods.

[1017] In some embodiments, the communication device 1100 further includes one or more memories 1102 for storing instructions. Optionally, all or part of the memory 1102 can also be outside the communication device 1100.

[1018] In some embodiments, the communication device 1100 further includes one or more transceivers 1103. When the communication device 1100 includes one or more transceivers 1103, the communication steps such as transmission and reception in the above method are performed by the transceiver 1103, and other steps are performed by the processor 1101.

[1019] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.

[1020] Optionally, the communication device 1100 further includes one or more interface circuits 1104, which are connected with the memory 1102. The interface circuit 1104 can be used to receive signals from the memory 1102 or other devices, and can be used to send signals to the memory 1102 or other devices. For example, the interface circuit 1104 can read the instructions stored in the memory 1102 and send the instructions to the processor 1101.

[1021] The communication device 1100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 1100 described in the present disclosure is not limited thereto, and the structure of the communication device 1100 can not be limited by FIG. 10A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[1022] FIG. 10B is a structural diagram of a chip according to an example embodiment. For the case where the communication device 1100 can be a chip or a chip system, reference can be made to the structural diagram of the chip 1200 shown in FIG. 10B, but not limited thereto.

[1023] The chip 1200 includes one or more processors 1201 for invoking instructions to cause the chip 1200 to perform any of the above communication methods.

[1024] In some embodiments, the chip 1200 further includes one or more interface circuits 1202 connected with the memory 1203, which can be used to receive signals from the memory 1203 or other devices, and can be used to send signals to the memory 1203 or other devices. For example, the interface circuit 1202 can read instructions stored in the memory 1203 and send the instructions to the processor 1201. Alternatively, the terms interface circuit, interface, transceiver pin, transceiver, and the like can be replaced with each other.

[1025] In some embodiments, the chip 1200 further includes one or more memories 1203 for storing instructions. Alternatively, all or part of the memory 1203 can be outside the chip 1200.

[1026] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 1100, cause the communication device 1100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer-readable storage medium, but can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.

[1027] The present disclosure also proposes a program product comprising a program and / or instructions which, when executed by the communication device 1100, cause the communication device 1100 to perform any of the above methods. Optionally, the program product is a computer program product. Optionally, the program product is stored on the storage medium.

[1028] The present disclosure also provides a computer program which, when running on a computer, causes the computer to perform any of the above communication methods.

[1029] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the present disclosure cover any and all variations of the present application which come within the scope of the following claims and their equivalents. It is intended that the specification and examples be considered exemplary only, with the true scope and spirit of the application being indicated by the following claims.

[1030] It is to be understood that the application is not limited to the precise details of construction and the arrangement of components described above and illustrated in the drawings and that various modifications and changes can be made without departing from the scope thereof, the scope being indicated by the claims.

Claims

A data security processing method, wherein, The method is performed by a terminal, the method comprising: sending, to a first node, a first message, the first message being used for the second node to determine a first security algorithm; receiving a second message sent by the first node; the second message being provided by the second node and the second message being used for the terminal to determine the first security algorithm; generating a second key based on the first security algorithm and a first key; the second key being used for protecting a communication security between the terminal and the second node; the first key being generated according to a third key of a third node. The method of claim 1, wherein, The sending, to the first node, the first message comprises one of: sending, to the first node, a first radio resource control (RRC) message; the first RRC message comprising the first message protected by a fourth key; the fourth key being used for protecting a communication security between the terminal and the third node; sending, to the first node, a second RRC message; the second RRC message comprising the first message unprotected by a fourth key. According to the method of claim 2, wherein the first RRC message comprises at least one of: a first indicator indicating a message type of the first message; a second indicator indicating the first node to forward the first message to a third node; type information of the second node; an instance ID of the second node; or the second RRC message comprises at least one of: a first indicator indicating a message type of the first message; type information of the second node; an instance ID of the second node. The first RRC message or the second RRC message is protected by an access stratum (AS) security context of the terminal. The method according to claim 2 or 3, wherein The receiving the second message sent by the first node comprises: The method according to any one of claims 1 to 4, wherein receiving a third RRC message sent by the first node, the third RRC message comprising the second message, the second message being integrity protected by a fifth key; the fifth key being generated according to a sixth key and the first security algorithm. The second message comprises at least one of: The method according to any one of claims 1 to 5, wherein algorithm identification information used for identifying the first security algorithm; second information used for indicating a first capability of the terminal, the first capability being related to security. The generating the second key based on the first security algorithm and the first key comprises one of: The method of claim 6, wherein, generating the second key based on the first key and the algorithm identification information and algorithm type information; generating the second key based on the first key, the algorithm identification information and a length of the algorithm identification information, the algorithm type information and a length of the algorithm type information. The method further comprises: The method according to any one of claims 1 to 7, wherein sending, to the first node, a fourth RRC message, the fourth RRC message comprising an indication of a completion of the first security algorithm negotiation. The method further comprises: The method of claim 8, wherein, receiving a fifth RRC message sent by the first node, the fifth RRC message comprising a third message, the third message being a response message of the first message. The first message comprises at least one of: The method according to any one of claims 1 to 9, wherein non-access stratum (NAS) signaling; an identification (ID) of the terminal; ​ A first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node. The method of claim 10, wherein, The method further comprises one of the following: generating the first key according to the third key, the first count value and type information of the second node; generating the first key according to the third key, the first count value and an instance ID of the second node. A data security processing method, wherein, The method is performed by a second node, and the method comprises: receiving a first message sent by a first node or a third node, the first message being used for the second node to determine a first security algorithm; generating a fifth key based on the first security algorithm and a sixth key, the fifth key being used to protect communication security between the second node and a terminal; the sixth key being generated according to a third key of the third node; sending, by the first node, a second message to the terminal, the second message being used for the terminal to determine the first security algorithm. The method of claim 12, wherein, The receiving the first message sent by the first node or the third node comprises one of the following: receiving a fourth message sent by the third node, the fourth message comprising at least one of the following: the first message decoded based on a fourth key; the sixth key; second information used to indicate a first capability of the terminal, the first capability being related to security; identification information of the first node; address information of the first node; receiving a fifth message sent by the first node, the fifth message comprising at least one of the following: the first message unprotected by the fourth key; the second information used to indicate the first capability of the terminal, the first capability being related to security. The method further comprises: The method of claim 13, wherein, sending, to the third node, a sixth message, the sixth message being used to request the third node to generate the sixth key for the second node; receiving a seventh message sent by the third node, the seventh message comprising the sixth key. The method further comprises: The method according to claim 13 or 14, wherein determining fourth information according to the second information and third information; the third information being used to indicate the first capability of the second node; the fourth information being used to indicate a first security algorithm selected by the second node. The fourth information comprises: The method of claim 15, wherein, algorithm identification information used to identify the first security algorithm. The generating the fifth key based on the first security algorithm and the sixth key comprises one of the following: The method of claim 16, wherein, generating the fifth key based on the sixth key, the algorithm identification information and algorithm type information; generating the fifth key based on the sixth key, the algorithm identification information, a length of the algorithm identification information, the algorithm type information and a length of the algorithm type information. The sending, by the first node, the second message to the terminal comprises: The method according to any one of claims 15 to 17, wherein performing integrity protection on the second message using the fifth key, the second message comprising at least one of the following: the fourth information; the second information; sending, by the first node, the second message to the terminal. The method further comprises: The method according to any one of claims 12 to 18, wherein receiving an indication that negotiation of the first security algorithm is completed, the indication being protected by a second key; the second key being used to protect communication security between the terminal and the second node; ​ sending, by the first node, a third message to the terminal, the third message being a response message of the first message, the third message being protected by the fifth key. A data security processing method, wherein, The method is performed by a third node, and the method comprises: generating a sixth key according to a third key of the third node; sending the sixth key to a second node, the sixth key being used by the second node to generate a fifth key, the fifth key being used to protect a communication between the second node and a terminal. The method of claim 20, wherein, The generating the sixth key according to the third key of the third node comprises: receiving an eighth message sent by a first node, the eighth message comprising a first message, the first message being protected by a fourth key, the fourth key being used to protect a communication between the terminal and the third node; decoding the first message by using the fourth key; generating the sixth key based on the third key and the decoded first message. The method of claim 21, wherein, The first message comprises at least one of: NAS signaling; an identity ID of the terminal; a first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node. The method of claim 21 or 22, wherein, The eighth message further comprises at least one of: type information of the second node; an instance ID of the second node. The method of claim 23, wherein, Before the generating the sixth key, the method further comprises: determining the second node according to at least one of the type information of the second node, the instance ID, a message type and information content. The method according to any one of claims 21 to 24, wherein The sending the sixth key to the second node comprises: sending, to the second node, a fourth message, the fourth message comprising at least one of: the first message decoded based on the fourth key; the sixth key; second information used to indicate a first capability of the terminal, the first capability being related to security; identity information of the first node; address information of the first node. The method of claim 20, wherein, The generating the sixth key according to the third key of the third node comprises: receiving a sixth message sent by the second node, the sixth message being used to request the third node to generate the sixth key for the second node; generating the sixth key based on the third key and the sixth message. The method of claim 26, wherein, The sixth message comprises at least one of: the terminal ID; the first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node. The method of claim 26 or 27, wherein, The sending the sixth key to the second node comprises: sending, to the second node, a seventh message, the seventh message comprising the sixth key. The method according to any one of claims 22 to 28, wherein The generating the sixth key according to the third key of the third node comprises one of: generating the sixth key according to the third key, a type of the second node and the first count value, the first count value being used to indicate a number of uplink messages sent by the terminal to the second node; generating the sixth key according to the third key, an instance identity ID of the second node and the first count value. A data security processing method, wherein, The method is performed by a first node, and the method comprises: receiving a first message sent by a terminal; sending the first message to a second node or a third node, the first message being used to make the second node determine a first security algorithm; receiving a second message sent by the second node; sending the second message to the terminal, the second message being used by the terminal to determine a first security algorithm; the first security algorithm being used by the terminal to generate a second key, the second key being used to protect a communication between the terminal and the second node. The method of claim 30, wherein, the first message sent by the terminal comprises one of: receiving a first RRC message sent by the terminal, the first RRC message comprising the first message protected by a fourth key, the fourth key being used to protect a communication between the terminal and the third node; receiving a second RRC message sent by the terminal; the second RRC message comprising the first message unprotected by the fourth key. The method of claim 31, wherein, the first RRC message comprises at least one of: a first indicator indicating a message type of the first message; a second indicator indicating that the first node forwards the first message to a third node; type information of the second node; an instance ID of the second node; or the second RRC message comprises at least one of: a first indicator indicating a message type of the first message; type information of the second node; an instance ID of the second node. The method of claim 32, wherein, the sending the first message to the third node comprises: sending an eighth message to a third node according to the first indicator or the second indicator in the first RRC message, the eighth message comprising the first message. The method of claim 32, wherein, the sending the first message to the second node comprises: sending a fifth message to the second node according to the type information of the second node and / or the instance ID of the second node in the second RRC message; the fifth message comprising at least one of: the first message unprotected by the fourth key; second information indicating a first capability of the terminal, the first capability being related to security. The method of any one of claims 30 to 34, wherein the sending the second message to the terminal comprises: sending a third RRC message to the terminal, the third RRC message comprising the second message, the second message being integrity protected by a fifth key; the fifth key being generated according to a sixth key and the first security algorithm; the fifth key being used to protect a communication between the second node and the terminal. The method of any one of claims 30 to 35, wherein, the method further comprises: receiving a fourth RRC message sent by the terminal, the fourth RRC message comprising an indication that the first security algorithm negotiation is completed; sending an indication that the first security algorithm negotiation is completed to the second node. the method further comprises: The method of claim 36, wherein, receiving a third message sent by the second node, the third message being protected by the fifth key; the third message being a response message of the first message; sending a fifth RRC message to the terminal, the fifth RRC message comprising the third message. performed by a communication system, the method comprising: A data security processing method, wherein, sending, by a terminal, a first message to a first node; sending, by the first node, the first message to a second node or a third node; the first message being used by the second node to determine a first security algorithm; generating, by the third node, a sixth key according to a third key of the third node; sending, by the third node, the sixth key to the second node; ​ The second node generates a fifth key based on the first security algorithm and a sixth key, the fifth key being used to protect communication security between the second node and the terminal; The second node sends a second message to the first node; The first node sends the second message to the terminal; the second message being used for the terminal to determine the first security algorithm; The terminal generates a second key based on the first security algorithm and a first key; the second key being used to protect communication security between the terminal and the second node; the first key being generated according to a third key of a third node. A terminal, wherein, The terminal comprises: a sending module configured to send a first message to a first node, the first message being used for a second node to determine a first security algorithm; a receiving module configured to receive a second message sent by the first node; the second message being provided by the second node and the second message being used for the terminal to determine the first security algorithm; a processing module configured to generate a second key based on the first security algorithm and a first key; the second key being used to protect communication security between the terminal and the second node; the first key being generated according to a third key of a third node. A second node, wherein, The second node comprises: a receiving module configured to receive a first message sent by the first node or the third node, the first message being used for the second node to determine a first security algorithm; a processing module configured to generate a fifth key based on the first security algorithm and a sixth key, the fifth key being used to protect communication security between the second node and a terminal; the sixth key being generated according to a third key of a third node; a sending module configured to send a second message to the terminal through the first node; the second message being used for the terminal to determine the first security algorithm. A third node, wherein The third node comprises: a processing module configured to generate a sixth key according to a third key of the third node; a sending module configured to send the sixth key to the second node, the sixth key being used for the second node to generate a fifth key, the fifth key being used to protect communication security between the second node and a terminal. A first node, wherein, The first node comprises: a receiving module configured to receive a first message sent by a terminal; a sending module configured to send the first message to a second node or a third node, the first message being used for the second node to determine a first security algorithm; The receiving module is further configured to receive a second message sent by the second node; The sending module is further configured to send the second message to the terminal, the second message being used for the terminal to determine the first security algorithm; the first security algorithm being used for the terminal to generate a second key, the second key being used to protect communication security between the terminal and the second node. A communication system wherein, The communication system comprises a terminal, a first node, a second node and a third node; the terminal is configured to implement the data security processing method in any one of claims 1 to 11, the second node is configured to implement the data security processing method in any one of claims 12 to 19, the third node is configured to implement the data security processing method in any one of claims 20 to 29, and the first node is configured to implement the data security processing method in any one of claims 30 to 37. A communication device, wherein, The communication device comprises: one or more processors; The processor is configured to invoke instructions to enable the communication device to implement the data security processing method in any one of claims 1 to 11, claims 12 to 19, claims 20 to 29, and claims 30 to 37. A storage medium, wherein, The storage medium stores instructions, which, when executed on the communication device, enable the communication device to implement the data security processing method in any one of claims 1 to 11, claims 12 to 19, claims 20 to 29, and claims 30 to 37. A program product, wherein, The program product comprises a computer program, which, when executed on the communication device, enables the communication device to implement the data security processing method in any one of claims 1 to 11, claims 12 to 19, claims 20 to 29, and claims 30 to 37.